首页> 外文会议>IEEE Joint Intelligence and Security Informatics Conference >Resilience of Anti-malware Programs to Na?ve Modifications of Malicious Binaries
【24h】

Resilience of Anti-malware Programs to Na?ve Modifications of Malicious Binaries

机译:对恶意杂志的反恶意软件程序的恢复能力进行恶意二进制文件

获取原文

摘要

The massive amounts of malware variants which are released each day demand fast in-lab analysis, along with fast in-field detection. Traditional malware detection methodology depends on either static or dynamic in-lab analysis to identify a suspicious file as malicious. When a file is identified as malware, the analyst extracts a structural signature, which is dispatched to subscriber machines. The signature should enable fast scanning, and should also be flexible enough to detect simple variants. In this paper we discuss 'nai?ve' variants which can be produced by a modestly skilled individual with publically accessible tools and knowhow which, if needed, can be found on the Internet. Furthermore, those variants can be derived directly from the malicious binary file, allowing anyone who has access to the binary file to modify it at his or her will. Modification can be automated, to produce large amounts of variants in short time. We describe several nai?ve modifications. We also put them to test against multiple antivirus products, resulting in significant decline of the average detection rate, compared to the original (unmodified) detection rate. Since the aforementioned decline may be related, at least in some cases, to avoidance of probable false positives, we also discuss the acceptable rate of false positives in the context of malware detection.
机译:每天释放的Malm软件变体都在实验室分析中快速释放,以及快速的现场检测。传统恶意软件检测方法取决于静态或动态的实验室分析,以将可疑文件标识为恶意。当文件被识别为恶意软件时,分析师提取一个结构签名,该结构签名被派遣到用户机器。签名应启用快速扫描,也应该足够灵活以检测简单的变体。在本文中,我们讨论了“Nai?ve”的变体,该变体可以由具有公开可访问的工具的适度熟练的个人生产,并且如果需要,可以在互联网上找到。此外,这些变体可以直接从恶意二进制文件中派生,允许任何可以访问二进制文件的人在他或她的意志中修改它。修改可以自动化,在短时间内产生大量变体。我们描述了几个Nai的修改。我们还将它们进行测试,以反对多种防病毒产品,导致平均检测率的显着下降,与原始(未修饰)检测率相比。由于上述下降可能与某些情况相关,以避免可能的误报,我们还在恶意软件检测的背景下讨论了误报的可接受率。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号