【24h】

Computing the Behavior of Malware

机译:计算恶意软件的行为

获取原文

摘要

As the quantity and sophistication of malicious code continues to grow, automation support for analysis becomes more important to keep pace with the scope and scale of the problem. To help address this need, CERT has been conducting research and development on Function Extraction (FX) technology for automated computation of software behavior, including malware behavior. Intruders often obfuscate malware packages to make analysis more difficult by inserting massive amounts of arbitrary jumps in code that thwart control flow tracing, and by adding blocks of no-op code that have no functional effect but must nevertheless be analyzed. A specialization of FX technology in the Function Extraction for Malicious Code (FX/MC) system is designed to address these obfuscation problems.
机译:随着恶意代码的数量和复杂性继续增长,自动化支持对于与问题的范围和规模保持同步,更为重要。为了帮助解决这种需求,CERT一直在进行研究和开发功能提取(FX)技术,用于自动计算软件行为,包括恶意软件行为。入侵者通常会使恶意软件包拆除恶意软件包来进行分析,通过在挫败控制流程跟踪的代码中插入大量的任意跳跃,以及通过添加没有功能效果的无op代码的块,但必须分析。 FX技术在恶意代码(FX / MC)系统中提取的FX技术专业旨在解决这些混淆问题。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号