首页> 外文会议>International Conference on Applied Materials and Manufacturing Technology >A Shellcode Detection Method Based on Full Native API Sequence and Support Vector Machine
【24h】

A Shellcode Detection Method Based on Full Native API Sequence and Support Vector Machine

机译:一种基于全本机API序列和支持向量机的ShellCode检测方法

获取原文
获取外文期刊封面目录资料

摘要

Dynamic monitoring the behavior of a program is widely used to discriminate between benign program and malware. It is usually based on the dynamic characteristics of a program, such as API call sequence or API call frequency to judge. The key innovation of this paper is to consider the full Native API sequence and use the support vector machine to detect the shellcode. We also use the Markov chain to extract and digitize Native API sequence features. Our experimental results show that the method proposed in this paper has high accuracy and low detection rate.
机译:动态监控程序的行为被广泛用于区分良性程序和恶意软件。它通常基于程序的动态特性,例如API呼叫序列或API呼叫频率来判断。本文的关键创新是考虑完整的本机API序列,并使用支持向量机检测Shellcode。我们还使用Markov链来提取和数字化本机API序列功能。我们的实验结果表明,本文提出的方法具有高精度和低检测率。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号