首页    期刊浏览 2024年11月29日 星期五
登录注册

文章基本信息

  • 标题:Analyzing Malware Based on Volatile Memory
  • 本地全文:下载
  • 作者:Hu, Liang ; Song, Shinan ; Zhang, Xiaolu
  • 期刊名称:Journal of Networks
  • 印刷版ISSN:1796-2056
  • 出版年度:2013
  • 卷号:8
  • 期号:11
  • 页码:2512-2519
  • DOI:10.4304/jnw.8.11.2512-2519
  • 语种:English
  • 出版社:Academy Publisher
  • 摘要:To explain the necessity of comprehensive and automatically analysis process for volatile memory, this paper summarized ordinarily analyzing methods and their common points especially for concerned data source. Then, a memory analysis framework Volatiltiy-2.2 and statistical output file size are recommended. In addition, to address the limitation of plug-ins classification in analyzing procedure, a user perspective classify is necessary and proposed. Furthermore, according to target data source differences on the base of result data set volume and employed relational method is introduced for comprehensive analysis guideline procedure. Finally, a test demo including DLLs loading order list analyzing is recommend, in which DLL load list is regard as different kind of characteristics typical data source with process and convert into process behavior fingerprint. The clustering for the fingerprint is employed string similar degree algorithm model in the demo, which has a wide range applications in traditional malware behavior analysis, and it is proposed that these methods also can be applied for volatile memory
  • 关键词:Malware Analysis;Volatile Memory;Data Classification;Behavior Analysis
国家哲学社会科学文献中心版权所有