首页> 外文会议>International Symposium on Computer Science and Its Application >PE File Header Analysis-based Packed PE File Detection Technique (PHAD)
【24h】

PE File Header Analysis-based Packed PE File Detection Technique (PHAD)

机译:PE文件报头基于分析的包装PE文件检测技术(PHAD)

获取原文

摘要

In order to conceal malware, malware authors use the packing and encryption techniques. If the malware is packed or encrypted, then it is very difficult to analyze. Therefore, to prevent the harmful effects of malware and to generate signatures for malware detection, the packed and encrypted executable codes must initially be unpacked. The first step of unpacking is to detect the packed executable files. In this paper, a packed file detection technique (PHAD) based on a PE Header Analysis is proposed. In many cases, to pack and unpack the executable codes, PE files have unusual attributes in their PE headers. In this paper, these characteristics are utilized to detect the packed files. A Characteristic Vector (CV) that consists of eight elements is defined, and the Euclidean distance (ED) of the CV is calculated. The EDs of the packed files are calculated and represent the base threshold for the detection of packed files.
机译:为了隐藏恶意软件,恶意软件作者使用包装和加密技术。如果恶意软件被包装或加密,那么很难分析。因此,为了防止恶意软件的有害影响和生成恶意软件检测的签名,必须最初未包装包装和加密的可执行代码。解压缩的第一步是检测包装的可执行文件。本文提出了一种基于PE报头分析的包装文件检测技术(PHAD)。在许多情况下,要打包和解压缩可执行代码,PE文件在其PE标题中具有异常属性。在本文中,利用这些特性来检测包装的文件。定义由八个元素组成的特征载体(CV),并且计算CV的欧几里德距离(ED)。计算包装文件的EDS并表示用于检测包装文件的基本阈值。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号