首页> 外文会议>IEEE International Carnahan Conference on Security Technology >A concept for monitoring self-transforming code using memory page access control management
【24h】

A concept for monitoring self-transforming code using memory page access control management

机译:使用内存页面访问控制管理监控自变换代码的概念

获取原文

摘要

Current antivirus software still focuses on using signature based algorithms on file content level to detect malware. Unfortunately, there is a simple way to circumvent this detection method: The malware author applies a code transformation algorithm (e.g. a packing or encryption scheme) to his malware plaintext and saves the reverse transformation algorithm along with the unsuspicious looking block of transformed mal-ware. Malware, which is obfuscated in that way, is called polymorphic malware. We call the transformation of the plaintext to the transformed malware as encoding and the reverse operation as decoding. Although current malware detection systems adopted and implemented several techniques to counter this, these methods are mostly either unreliable or suffer heavy performance drawbacks. We present a non-intrusive and lightweight method to monitor any executable code in real-time, which allows efficient detection of polymorphic malware.
机译:当前的防病毒软件仍然专注于使用基于签名的文件内容级别算法来检测恶意软件。不幸的是,存在一种简单的方法来规避这种检测方法:恶意软件作者将代码转换算法(例如包装或加密方案)应用于他的恶意软件明文并保存反向变换算法以及未验证的转换错误的MAL-WANT块。恶意软件,这种方式被滥用,称为多态恶意软件。我们称明文的转换为转换的恶意软件,作为编码和反向操作作为解码。虽然当前的恶意软件检测系统采用并实现了几种技术来对策,但这些方法主要是不可靠的或遭受沉重的性能缺点。我们提出了一种非侵入性和轻量级方法来实时监控任何可执行代码,这允许有效地检测多态恶意软件。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号