【24h】

Research on New PE File Packer and Shelling Methods

机译:新PE文件包装机和炮击方法研究

获取原文

摘要

The full name of PE file is Portable Executable file. The common EXE, DLL, OCX, SYS and COM documents are all PE files. File packer is a necessary means of application authors usually use to protect copyrights, but it can be used by many malicious softwares to avoid the detection of anti-virus softwares. Common shelling softwares usually deal with these programs by finding the feature codes of the targeted packer files, while directional shelling softwares usually find by specified features which have already been concluded by Network Security engineers, However, with the development of shell protection, more and more shell applications can't be processed by common shelling softwares as well as directional shelling softwares. To solve the threat of these malicious softwares, new shelling methods must be developed. The paper introduces new shelling and packing ways, and focuses on introducing principals and applications of these techniques.
机译:PE文件的全名是可移植的可执行文件。常见的EXE,DLL,OCX,SYS和COM文件都是PE文件。文件包装器是应用作者通常用于保护版权的必要手段,但可以由许多恶意软件使用,以避免检测防病毒软件。常见的shelling软件通常通过查找目标包装文件的特征代码来处理这些程序,而定向shelling软件通常通过网络安全工程师已经结束的指定特征,然而,随着壳牌保护的发展,越来越多壳牌应用程序无法通过常见的壳软件以及方向壳软件来处理。为解决这些恶意软件的威胁,必须开发出新的脱壳方法。本文介绍了新的炮击和包装方式,专注于引入这些技术的原理和应用。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号