【24h】

A New Approach to Malware Detection

机译:恶意软件检测的新方法

获取原文

摘要

Malware has become one of the most serious threats to computer users. Early techniques based on syntactic signatures can be easily bypassed using program obfuscation. A promising direction is to combine Control Flow Graph (CFG) with instruction-level information. However, since previous work includes only coarse information, i.e., the classes of instructions of basic blocks, it results in false positives during the detection. To address this issue, we propose a new approach that generates formalized expressions upon assignment statements within basic blocks. Through combining CFG with the functionalities of basic blocks, which are represented in terms of upper variables with their corresponding formalized expressions and system calls (if any), our approach can achieve more accurate malware detection compared to previous CFG-based solutions.
机译:恶意软件已成为计算机用户最严重的威胁之一。使用程序混淆可以轻松绕过基于语法签名的早期技术。有希望的方向是将控制流程图(CFG)与指令级信息组合。然而,由于以前的工作仅包括粗略信息,即基本块的指令类别,因此它会导致检测期间的误报。要解决此问题,我们提出了一种新的方法,在基本块中的分配陈述时会生成正式的表达式。通过将CFG与基本块的功能组合,这些块与上变量以相应的形式化的表达式和系统调用表示(如果有的话),我们的方法可以实现与以前的基于CFG的解决方案相比更准确的恶意软件检测。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号