【24h】

A Study of the Packer Problem and Its Solutions

机译:包装商问题及其解决方案研究

获取原文

摘要

An increasing percentage of malware programs distributed in the wild are packed by packers, which are programs that transform an input binary's appearance without affecting its execution semantics, to create new malware variants that can evade signature-based malware detection tools. This paper reports the results of a comprehensive study of the extent of the packer problem based on data collected at Symantec and the effectiveness of existing solutions to this problem. Then the paper presents a generic unpacking solution called Justin (Just-In-Time AV scanning), which is designed to detect the end of unpacking of a packed binary's run and invoke AV scanning against the process image at that time. For accurate end-to-unpacking detection, Justin incorporates the following heuristics: Dirty Page Execution, Unpacker Memory Avoidance, Stack Pointer Check and Command-Line Argument Access. Empirical testing shows that when compared with SymPack, which contains a set of manually created unpackers for a collection of selective packers, Justin's effectiveness is comparable to SymPack for those binaries packed by these supported packers, and is much better than SymPack for binaries packed by those that SymPack does not support.
机译:越来越大的恶意软件程序百分比由包装器包装,它们是在不影响其执行语义的情况下转换输入二进制外观的程序,以创建可以避免基于签名的恶意软件检测工具的新恶意软件变体。本文报告了基于在赛门铁克收集的数据和解决此问题的现有解决方案的有效性的数据库综合研究结果。然后本文介绍了一个名为Justin(即时AV扫描)的通用解包解决方案,旨在检测打开包装的二进制运行的结束,并在此时间调用AV扫描。为了准确的端到解压缩检测,Justin包含以下启发式:脏页执行,解压缩存储器避免,堆栈指针检查和命令行参数访问。实证测试表明,与Sympack相比,其中包含用于集合的一组手动创建的未包装器,justin的有效性与这些支持的包装器包装的那些二进制文件的逻辑相当,并且比那些包装的二进制文件的Sympack更好该突击人不支持。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号