中国科学院软件研究所机构知识库
Advanced  
ISCAS OpenIR  > 软件所图书馆  > 期刊论文
Subject: Computer Science
Title:
基于语义的恶意代码行为特征提取及检测方法
Alternative Title: semantics-based malware behavior signature extraction and detection method
Author: 王蕊 ; 冯登国 ; 杨轶 ; 苏璞睿
Keyword: malware ; semantics ; behavior signature extraction ; malware detection
Source: Journal of Software
Issued Date: 2012
Volume: 23, Issue:2, Pages:378-393
Indexed Type: cscd,ei,wanfang
Department: 王蕊, 中国科学院研究生院, 信息安全国家重点实验室, 北京 100049, 中国. 冯登国, 中国科学院研究生院, 北京 100049, 中国. 杨轶, 中国科学院软件研究所, 北京 100190, 中国. 苏璞睿, 中国科学院软件研究所, 北京 100190, 中国.
Abstract: 提出一种基于语义的恶意代码行为特征提取及检测方法,通过结合指令层的污点传播分析与行为层的语义分析,提取恶意代码的关键行为及行为间的依赖关系;然后 ,利用抗混淆引擎识别语义无关及语义等价行为,获取具有一定抗干扰能力的恶意代码行为特征。在此基础上,实现特征提取及检测原型系统。通过对多个恶意代码 样本的分析和检测,完成了对该系统的实验验证。实验结果表明,基于上述方法提取的特征具有抗干扰能力强等特点,基于此特征的检测对恶意代码具有较好的识别 能力.
English Abstract: This paper proposes a semantic-based approach to malware behavioral signature extraction and detection.This approach extracts critical malware behaviors as well as dependencies among these behaviors,integrating instruction-level taint analysis and behavior-level semantics analysis.Then,it acquires anti-interference malware behavior signatures using anti-obfuscation engine to identify semantic irrelevance and semantically equivalence.Further,a prototype system based on this signature extraction and detection approach is developed and evaluated by multiple malware samples.Experimental results have demonstrated that the malware signatures extracted show good ability to anti obfuscation and the detection based on theses signatures could recognize malware variants effectively.
Language: 中文
Content Type: 期刊论文
URI: http://ir.iscas.ac.cn/handle/311060/14657
Appears in Collections:软件所图书馆_期刊论文

Files in This Item:
File Name/ File Size Content Type Version Access License
基于语义的恶意代码行为特征提取及检测方法.pdf(1231KB)----限制开放 联系获取全文

Recommended Citation:
王蕊,冯登国,杨轶,等. 基于语义的恶意代码行为特征提取及检测方法[J]. Journal of Software,2012-01-01,23(2):378-393.
Service
Recommend this item
Sava as my favorate item
Show this item's statistics
Export Endnote File
Google Scholar
Similar articles in Google Scholar
[王蕊]'s Articles
[冯登国]'s Articles
[杨轶]'s Articles
CSDL cross search
Similar articles in CSDL Cross Search
[王蕊]‘s Articles
[冯登国]‘s Articles
[杨轶]‘s Articles
Related Copyright Policies
Null
Social Bookmarking
Add to CiteULike Add to Connotea Add to Del.icio.us Add to Digg Add to Reddit
所有评论 (0)
暂无评论
 
评注功能仅针对注册用户开放,请您登录
您对该条目有什么异议,请填写以下表单,管理员会尽快联系您。
内 容:
Email:  *
单位:
验证码:   刷新
您在IR的使用过程中有什么好的想法或者建议可以反馈给我们。
标 题:
 *
内 容:
Email:  *
验证码:   刷新

Items in IR are protected by copyright, with all rights reserved, unless otherwise indicated.

 

 

Valid XHTML 1.0!
Copyright © 2007-2019  中国科学院软件研究所 - Feedback
Powered by CSpace