首页> 外文OA文献 >Analysis of Evasion Techniques in Web-based Malware
【2h】

Analysis of Evasion Techniques in Web-based Malware

机译:基于Web的恶意软件中的逃避技术分析

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

Web-based mechanisms, often mediated by malicious JavaScript code, play an important role in malware delivery today, making defenses against web-based malware crucial for system security. To make it even more challenging, malware authors often take advantage of various evasion techniques to evade detection. As a result, a constant arms race of evasion and detection techniques between malware authors and security analysts has led to advancement in code obfuscation and anti-analysis techniques. This dissertation focuses on the defenses against web-based malware protected by advanced evasion techniques from both defensive and offensive perspectives. From a defensive perspective, we examine existing evasion techniques and propose deobfuscation and detection approaches to defeating some popular techniques used by web-based malware today. In the case of code-unfolding based obfuscation, we use a semantics-based approach to simplify away obfuscations by identifying code that is relevant to the behavior of the original program. In the case of environment-dependent malware, we propose environmental predicate, which detects behavior discrepancy of JavaScript program between targeted browser and detector sandbox, therefore protecting users from possible detection false negatives caused by environmental triggers. From an offensive perspective, we analyze existing detection techniques to examining their assumptions and study how these assumptions can be broken. We also propose a combination of obfuscation and anti-analysis techniques, targeting these limitations, which can hide existing web-based malware from state-of-the-art detectors.
机译:基于Web的机制通常由恶意JavaScript代码介导,在当今的恶意软件分发中扮演着重要角色,因此针对基于Web的恶意软件的防御对于系统安全至关重要。为了使其更具挑战性,恶意软​​件作者经常利用各种逃避技术来逃避检测。结果,恶意软件作者和安全分析人员之间不断发生的逃避和检测技术军备竞赛,导致了代码混淆和反分析技术的发展。本文从防御和攻击的角度着眼于针对由高级规避技术保护的基于Web的恶意软件的防御。从防御的角度来看,我们研究了现有的规避技术,并提出了消除混淆和检测方法,以克服当今基于网络的恶意软件所使用的一些流行技术。在基于代码展开的混淆中,我们使用基于语义的方法通过识别与原始程序的行为相关的代码来简化混淆。对于与环境有关的恶意软件,我们提出了环境谓词,该谓词可以检测目标浏览器和检测器沙箱之间JavaScript程序的行为差异,从而保护用户免受环境触发因素造成的可能的检测误报。从进攻角度来看,我们分析了现有的检测技术以检查其假设,并研究如何打破这些假设。我们还针对这些限制提出了混淆和反分析技术的组合,可以将这些基于Web的恶意软件隐藏在最新的检测器中。

著录项

  • 作者

    Lu Gen;

  • 作者单位
  • 年度 2013
  • 总页数
  • 原文格式 PDF
  • 正文语种 en_US
  • 中图分类

相似文献

  • 外文文献
  • 中文文献
  • 专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号