首页> 外文期刊>Security and Communications Networks >A dynamic malware analyzer against virtual machine aware malicious software
【24h】

A dynamic malware analyzer against virtual machine aware malicious software

机译:针对虚拟机感知的恶意软件的动态恶意软件分析器

获取原文
获取原文并翻译 | 示例
       

摘要

Nowadays, cyber-world is being enriched by a large variety of digital information technology-based services. An increasing rate of remote and mobile usage leads to a remarkable dependency on information security. Analysis and detection of malicious software or so-called malware is a challenging task due to the introduction of advanced obfuscation techniques by malware authors. In this study, we mainly concentrate on anti-virtual machine evasion techniques to provide secure and reproducible environments for malware analysis and its implementation issues. Malwares are identified on the basis of their behaviors by taking precautions related to the anti-virtual machine detection techniques. The dynamic malware analyzer tool is deployed to execute anti-virtual machine-aware malware samples in VMware environment. Dynamic malware analyzer monitors system resources such as connections, processes, windows registry, and file operations. Success ratio of detection is tested by using public malware sets with an accuracy of 92%. The effectiveness and success of the behavior-based malware analyzer tool is exploited and current state of the art of malware detection schemes is presented. Copyright (c) 2013 John Wiley & Sons, Ltd.
机译:如今,网络世界因各种基于数字信息技术的服务而变得越来越丰富。远程和移动使用率的增加导致对信息安全的极大依赖。由于恶意软件作者引入了先进的混淆技术,因此分析和检测恶意软件或所谓的恶意软件是一项具有挑战性的任务。在这项研究中,我们主要集中于反虚拟机规避技术,以提供安全且可重现的环境来进行恶意软件分析及其实现问题。通过采取与反虚拟机检测技术有关的预防措施,根据恶意软件的行为来识别它们。部署了动态恶意软件分析器工具,以在VMware环境中执行反虚拟机感知的恶意软件样本。动态恶意软件分析器监视系统资源,例如连接,进程,Windows注册表和文件操作。通过使用公共恶意软件集来测试检测的成功率,准确性为92%。利用了基于行为的恶意软件分析器工具的有效性和成功性,并介绍了恶意软件检测方案的最新技术水平。版权所有(c)2013 John Wiley&Sons,Ltd.

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号