首页    期刊浏览 2024年11月03日 星期日
登录注册

文章基本信息

  • 标题:Methods of bypassing anti-debugging APIs for security test
  • 本地全文:下载
  • 作者:Seung-Hwan Lee ; Hyo-Jeong Shin ; Hyong-Shik Kim
  • 期刊名称:Journal of Security Engineering
  • 印刷版ISSN:1738-7531
  • 出版年度:2018
  • 卷号:15
  • 期号:1
  • 页码:25-40
  • 出版社:SERSC
  • 摘要:The importance of detecting malwares has increased as their damages become severe, however it ismuch difficult to test the malwares, which are written to bypass such detection techniques. In order to testthe malwares using investigation tools including debuggers, we may have to develop methods to bypassanti-debugging APIs usually found in the malwares. In this paper, we deal with such methods of bypassinganti-debugging APIs for the purpose of security test on malwares.First, we classify the anti-debugging techniques into three categories and investigate their workingmechanism in high-level language. Then, we explain our four methods of bypassing anti-debugging APIs inmachine instruction level. The experimental results show that our methods could effectively bypassanti-debugging APIs.The proposed methods could improve the effectiveness of malware test, if applied before the test.
  • 关键词:malicious code; anti-debugging API; security test; instruction substitution.
国家哲学社会科学文献中心版权所有