首页    期刊浏览 2024年11月24日 星期日
登录注册

文章基本信息

  • 标题:ARCHITECTURE OF MALWARE DETECTOR FOR OBFUSCATED CODE INSPECTION
  • 本地全文:下载
  • 作者:LEE LING CHUAN ; MAHAMOD ISMAIL ; KASMIRAN JUMARI
  • 期刊名称:Journal of Theoretical and Applied Information Technology
  • 印刷版ISSN:1992-8645
  • 电子版ISSN:1817-3195
  • 出版年度:2013
  • 卷号:49
  • 期号:1
  • 出版社:Journal of Theoretical and Applied
  • 摘要:Signature-based malware detection is a very fundamental technique that detects malware by generating signatures. The detection however, is unable to detect obfuscated malware unless pre-generated signature is stored in the database. In this paper, we propose a combination of known packer detection, unpacking module, and heuristic scanning techniques to find and block a malicious program before it manages to be executed locally. Unpacking is the process of stripping packer layers and restoring the original contents. This module contains self-decryption script bodies that are devised to detect and extract the hidden-code bodies of obfuscated malware. Hence, the scanning process only deals with real malware body but not junk block or junk subroutine code. This paper also draws up the implementation and the evaluation of our virus scanning mechanisms. Finally, we present experimental results of our proposed techniques and the results show that our test set is highly accurate.
  • 关键词:Malware Detector; Obfuscated; Unpacking; Emulator; Disassembler
国家哲学社会科学文献中心版权所有