首页> 外文期刊>IEICE transactions on information and systems >Executable Code Recognition in Network Flows Using Instruction Transition Probabilities
【24h】

Executable Code Recognition in Network Flows Using Instruction Transition Probabilities

机译:Executable Code Recognition in Network Flows Using Instruction Transition Probabilities

获取原文
获取原文并翻译 | 示例
       

摘要

The ability to recognize quickly inside network flows to be executable is prerequisite for malware detection. For this purpose, we introduce an instruction transition probability matrix (ITPX) which is comprised of the IA-32 instruction sets and reveals the characteristics of executable code's instruction transition patterns. And then, we propose a simple algorithm to detect executable code inside network flows using a reference ITPX which is learned from the known Windows Portable Executable files. We have tested the algorithm with more than thousands of executable and non-executable codes. The results show that it is very promising enough to use in real world.

著录项

获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号