首页> 外文期刊>Wireless personal communications: An Internaional Journal >A Framework for Recognition and Confronting of Obfuscated Malwares Based on Memory Dumping and Filter Drivers
【24h】

A Framework for Recognition and Confronting of Obfuscated Malwares Based on Memory Dumping and Filter Drivers

机译:基于内存转储和过滤驱动程序的识别和面对混淆恶意的框架

获取原文
获取原文并翻译 | 示例
       

摘要

In this paper obfuscation techniques used by novel malwares presented and compared. IAT smashing, string encryption and dynamic programing are explained in static methods and hooking at user and kernel level of OS with DLL injection, modifying of SSDT and IDT table addresses, filter IRPs, and possessor emulation are techniques in dynamic methods. This paper suggest Approach for passing through malware obfuscation techniques. In order that it can analyze malware behaviors. Our methods in proposed approach are detection presence time of a malware at user and kernel level of OS, dumping of malware executable memory at correct time and precise hook installing. Main purpose of this paper is establishment of an efficient platform to analyze behavior and detect novel malwares that by use of metamorphic engine, packer and protector tools take action for obfuscation and metamorphosis of themself. At final, this paper use a dataset embeds different kind of obfuscated and metamorphic malwares in order to prove usefulness of its methods experiments. Show that proposed methods can confront most malware obfuscation techniques. It evaluated success rate to unpacking, obfuscated malwares and it shows 85% success rate to recognize kernel level malwares.
机译:在本文呈现和比较的新型恶魔用的纸张混淆技术中。 IAT SMASHING,String加密和动态编程是以静态方法解释的,并在用户和内核级别使用DLL注入,修改SSDT和IDT表地址,滤波器IRP和占有器仿真是动态方法的技术。本文建议通过恶意软件混淆技术的方法。为了分析恶意软件行为。我们在所提出的方法中的方法是检测用户和内核级别的恶意软件的存在时间,在正确的时间和精确的挂钩安装时转储恶意软件可执行内存。本文的主要目的是建立一个有效的平台,用于分析行为,并通过使用变质发动机,包装机和保护工具来探测新的恶意,采取行动,以便对自己的混淆和变态。在最终时,本文使用数据集嵌入不同类型的混淆和变质恶意,以证明其方法实验的实用性。显示提出的方法可以面对大多数恶意软件混淆技术。它评估了取消包装,混淆的恶意恶魔的成功率,并显示85%的成功率,以识别内核水平的恶意。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号