首页> 外文会议>International conference on rough sets and knowledge technology >A Study on Similarity Calculation Method for API Invocation Sequences
【24h】

A Study on Similarity Calculation Method for API Invocation Sequences

机译:API调用序列的相似性计算方法研究

获取原文

摘要

Malware variants have been developed and spread in the Internet, and the number of new malware variants is increases every year. Recently, malware is applied with obfuscation and mutation techniques to hide its existence, and malware variants are developed with various automatic tools that transform the properties of existing malware to avoid static analysis based malware detection systems. It is difficult to detect such obfuscated malware with static-based signatures, so we have designed a detection system based on dynamic analysis. In this paper, we propose a dynamic analysis based system that uses the API invocation sequences to compare behaviors of suspicious software with behaviors of existing malware.
机译:恶意软件变体已经在互联网上开发并传播,每年都会增加新的恶意软件变体。最近,使用混淆和突变技术来应用恶意软件来隐藏其存在,并且使用各种自动工具开发恶意软件,可转换现有恶意软件的属性以避免基于静态分析的恶意软件检测系统。很难通过基于静态的签名检测这种混淆的恶意软件,因此我们设计了一种基于动态分析的检测系统。在本文中,我们提出了一种基于动态分析的系统,它使用API​​调用序列与现有恶意软件的行为比较可疑软件的行为。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号