中国科学院软件研究所机构知识库
Advanced  
ISCAS OpenIR  > 软件所图书馆  > 期刊论文
Subject: Computer Science (provided by Thomson Reuters)
Title:
基于动态污点分析的恶意代码通信协议逆向分析方法
Alternative Title: communication protocol reverse engineering of malware using dynamic taint analysis
Author: 刘豫 ; 王明华 ; 苏璞睿 ; 冯登国
Keyword: Computer crime ; Semantics ; Syntactics
Source: 电子学报
Issued Date: 2012
Volume: 40, Issue:4, Pages:661-668
Indexed Type: cnki,ei,cscd,wanfang
Department: 中国科学院软件研究所信息安全国家重点实验室;
Abstract: 对恶意代码通信协议的逆向分析是多种网络安全应用的重要基础.针对现有方法在协议语法结构划分的完整性和准确性方面存在不足,对协议字段的语义理解尤为薄弱,提出了一种基于动态污点分析的协议逆向分析方法,通过构建恶意进程指令级和函数级行为的扩展污点传播流图(Extended Taint Propagation Graph,ETPG),完成对协议数据的语法划分和语义理解.通过实现原型系统并使用恶意代码样本进行测试,结果表明本方法可以实现有效的语法和语义分析,具有较高的准确性和可靠性.
English Abstract: Communication protocol reverse engineering of malwares is significant base for various network security applications. However, recent works have limited accuracy and integrity in identifying protocol fields and are especially weak in understanding fields' semantics. This paper proposed a method for communication protocol reverse engineering based on dynamic taint analysis. By building an extended taint propagation graph (ETPG) recording both instruction and function level behaviors of a malicious process, dividing the protocol data into different syntax fields and inducing the semantic information of individual fields were achieved. A prototype system was implemented and evaluated with malware samples. The results show that this method can divide the syntax fields and extract semantic information accurately and effectively.
Language: 中文
Content Type: 期刊论文
URI: http://ir.iscas.ac.cn/handle/311060/14675
Appears in Collections:软件所图书馆_期刊论文

Files in This Item:
File Name/ File Size Content Type Version Access License
基于动态污点分析的恶意代码通信协议逆向分析方法.pdf(898KB)----限制开放 联系获取全文

Recommended Citation:
刘豫,王明华,苏璞睿,等. 基于动态污点分析的恶意代码通信协议逆向分析方法[J]. 电子学报,2012-01-01,40(4):661-668.
Service
Recommend this item
Sava as my favorate item
Show this item's statistics
Export Endnote File
Google Scholar
Similar articles in Google Scholar
[刘豫]'s Articles
[王明华]'s Articles
[苏璞睿]'s Articles
CSDL cross search
Similar articles in CSDL Cross Search
[刘豫]‘s Articles
[王明华]‘s Articles
[苏璞睿]‘s Articles
Related Copyright Policies
Null
Social Bookmarking
Add to CiteULike Add to Connotea Add to Del.icio.us Add to Digg Add to Reddit
所有评论 (0)
暂无评论
 
评注功能仅针对注册用户开放,请您登录
您对该条目有什么异议,请填写以下表单,管理员会尽快联系您。
内 容:
Email:  *
单位:
验证码:   刷新
您在IR的使用过程中有什么好的想法或者建议可以反馈给我们。
标 题:
 *
内 容:
Email:  *
验证码:   刷新

Items in IR are protected by copyright, with all rights reserved, unless otherwise indicated.

 

 

Valid XHTML 1.0!
Copyright © 2007-2021  中国科学院软件研究所 - Feedback
Powered by CSpace