首页> 外文会议>International Conference on Network and System Security >Automated extraction of polymorphic virus signatures using abstract interpretation
【24h】

Automated extraction of polymorphic virus signatures using abstract interpretation

机译:使用抽象解释自动提取多态病毒签名

获取原文

摘要

In this paper, we present a novel approach for the detection and signature extraction for a subclass of polymorphic computer viruses. Our detection scheme offers 0 false negative and a very low false positives detection rate. We use context-free grammars as viral signatures, and design a process able to extract this signature from a single sample of a virus. Signature extraction is achieved through a light manual information gathering process, followed by an automatic static analysis of the binary code of the virus mutation engine.
机译:在本文中,我们提出了一种用于多态性计算机病毒的子类的检测和签名提取的新方法。我们的检测方案提供0假阴性和非常低的误报检测率。我们将免费语法用作病毒签名,并设计能够从病毒的单个样本中提取此签名的过程。通过轻型手动信息收集过程实现签名提取,然后通过对病毒突变引擎的二进制代码进行自动静态分析。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号