...
首页> 外文期刊>Bell Labs technical journal >Polymorphic Malware Detection and Identification via Context-Free Grammar Homomorphism
【24h】

Polymorphic Malware Detection and Identification via Context-Free Grammar Homomorphism

机译:通过上下文无关语法同态进行多态恶意软件检测和识别

获取原文
获取原文并翻译 | 示例

摘要

Computer viruses continue to proliferate despite the use of virus detection systems (VDS). This is due to VDS inability to detect variants not represented in signature databases. Detection systems look for contiguous byte sequences, use regular expressions for noncontiguous sequences, or detect initial behavior within a sandbox. Recent research has focused on using control-flow graph isomorphism in detection. These techniques are ineffective at detecting some polymorphs, which change their byte sequences and initial behavior and produce nonisomorphic control-flow graphs. Our approach compares program hierarchical structure. We observed that polymorphic instances are variants of the same program, these variants use the same algorithm, and a program's algorithm determines its hierarchical structure. Our technique maps a program's hierarchical structure to a context-free grammar, normalizes the grammar, and uses a fast check for homomorphism between the normalized grammars.
机译:尽管使用了病毒检测系统(VDS),计算机病毒仍在继续扩散。这是由于VDS无法检测签名数据库中未表示的变体。检测系统查找连续的字节序列,对不连续的序列使用正则表达式,或检测沙箱中的初始行为。最近的研究集中在检测中使用控制流图同构。这些技术不能有效地检测某些多态性,这些多态性会改变其字节序列和初始行为,并产生非同构的控制流图。我们的方法比较程序的层次结构。我们观察到多态实例是同一程序的变体,这些变体使用相同的算法,并且程序的算法确定其分层结构。我们的技术将程序的层次结构映射到上下文无关的语法,对语法进行规范化,并使用快速检查规范化语法之间的同构性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号