首页> 外文期刊>Journal in computer virology >Improving antivirus accuracy with hypervisor assisted analysis
【24h】

Improving antivirus accuracy with hypervisor assisted analysis

机译:借助Hypervisor辅助分析提高防病毒准确性

获取原文
获取原文并翻译 | 示例
           

摘要

Modern malware protection systems bring an especially difficult problem to antivirus scanners. Simple obfuscation methods can diminish the effectiveness of a scanner significantly, often times rendering them completely ineffective. This paper outlines the usage of a hypervisor based deobfuscation engine that greatly improves the effectiveness of existing scanning engines. We have modified the Ether malware analysis framework to add the following features to deobfuscation: section and header rebuilding and automated kernel virtual address descriptor import rebuilding. Using these repair mechanisms we have shown as high as 45% improvement in the effectiveness of antivirus scanning engines.
机译:现代恶意软件防护系统给防病毒扫描程序带来了特别困难的问题。简单的混淆方法可能会大大降低扫描仪的效率,常常使它们完全无效。本文概述了基于虚拟机管理程序的去模糊引擎的用法,该引擎大大提高了现有扫描引擎的效率。我们修改了Ether恶意软件分析框架,为反混淆添加了以下功能:节和标头重建以及自动内核虚拟地址描述符导入重建。使用这些修复机制,我们已经显示出防病毒扫描引擎的效率提高了45%。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号