首页> 外文会议>IEEE International Carnahan Conference on Security Technology >A theoretical implementation of Blended Program Analysis for virus signature extraction
【24h】

A theoretical implementation of Blended Program Analysis for virus signature extraction

机译:病毒签名提取混合计划分析的理论实现

获取原文

摘要

Usually, two methods are used in order to detect a virus viz. Signature detection and Anomaly detection. In this paper, we'll talk about the signature extraction process. Virus signatures can be extracted by analyzing the virus in a safe environment usually provided by a sandbox or a virtual machine. We can define the virus analysis as “the action of taking virus apart in order to study it”. The analysis is done by implementing the methods of program analysis. Traditionally, there were two methods of program analysis viz. Static Program Analysis and Dynamic Program Analysis. Recently, a new method has been invented called Blended Program Analysis. This method combines a dynamic representation of the program calling structure, with a static analysis applied to a region of that calling structure with observed performance problems. In the malware's perspective, a performance problem can be substituted with activities like registry editing or other such activities that result into a system failure. In this paper, we'll explore the possibilities of extracting the signatures of viruses, including complex viruses such as macro viruses, by making use of Blended Program Analysis. Since, this paper is a theoretical study we won't be dealing with any kind of experiments or experimental data.
机译:通常,使用两种方法以检测病毒viz。签名检测和异常检测。在本文中,我们将讨论签名提取过程。可以通过在通常由沙箱或虚拟机提供的安全环境中分析病毒来提取病毒签名。我们可以将病毒分析定义为“采取病毒分开的动作以研究它”。通过实施程序分析方法来完成分析。传统上,有两种程序分析viz。静态程序分析和动态程序分析。最近,已经发明了一种称为混合程序分析的新方法。该方法组合了程序调用结构的动态表示,其静态分析应用于具有观察到性能问题的调用结构的区域。在恶意软件的角度来看,性能问题可以用registry编辑或其他此类活动的活动替换,导致系统故障。在本文中,通过利用混合的程序分析,我们将探讨提取病毒签名的可能性,包括复杂病毒,如宏病毒。从此,本文是一个理论研究,我们不会处理任何类型的实验或实验数据。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号