【24h】

Taint-Graph-Based for Automatic Spyware Analysis

机译:基于污染图的自动间谍软件分析

获取原文

摘要

Spyware is a kind of malicious code that is installed on victims' machines without their content. They spy on the users' behavior and compromise their privacy, while transmitting sensitive information to some remote servers. Current anti-spyware tools are similar to anti-virus products in that they identify known spyware by comparing the binary image to a database of signatures. Unfortunately, these techniques cannot distinguish some novel spyware, require frequent updates to signature databases, and are easy to elude by code obfuscation. In this paper, we introduce a novel analysis approach that tracks the sensitive information flow through the system. Trough our analysis to obtained data, we can identify unknown program or components as spyware and gain detail information. For example, which sensitive data is leaked and where it is sent.
机译:间谍软件是一种恶意代码,被安装在受害者的机器上而没有其内容。它们监视用户的行为并损害他们的隐私,同时将敏感信息传输到某些远程服务器。当前的反间谍软件工具与反病毒产品相似,因为它们通过将二进制映像与签名数据库进行比较来识别已知的间谍软件。不幸的是,这些技术无法区分某些新颖的间谍软件,需要经常更新特征库,并且容易被代码混淆所掩盖。在本文中,我们介绍了一种新颖的分析方法,该方法可跟踪通过系统的敏感信息流。通过对获得的数据进行分析,我们可以将未知程序或组件识别为间谍软件并获取详细信息。例如,哪些敏感数据泄漏以及将其发送到何处。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号