首页    期刊浏览 2024年11月08日 星期五
登录注册

文章基本信息

  • 标题:On Analysis and Effectiveness of Signature Based in Detecting Metamorphic Virus
  • 本地全文:下载
  • 作者:Imran Edzereiq Kamarudin ; Syahrizal Azmir Md Sharif ; Tutut Herawan
  • 期刊名称:International Journal of Security and Its Applications
  • 印刷版ISSN:1738-9976
  • 出版年度:2013
  • 卷号:7
  • 期号:4
  • 出版社:SERSC
  • 摘要:Computer viruses and other forms of malware have viewed as a threat to any software system. They have the capability to deliver a malicious infection. A common technique that virus writers use to avoid detection is to enable the virus to change itself by having some kind of self-modifying code. This kind of virus is commonly known as a metamorphic virus, and can be particularly difficult to detect. Metamorphic viruses have a potential to avoid any signature-based detection schemes by implementing code obfuscation techniques in an effort to defeat it. In metamorphic virus, if dead code is added and the control flow is changed sufficiently by inserting jump statements, the virus cannot be detected. In this paper we first developed a code obfuscation engine. We then used this engine to create metamorphic variants of a seed virus and performed the validity of the statement about metamorphic viruses and signature based detectors. Last but not least, we have propose a profile which enclose the information about the existing metamorphic viruses infection
  • 关键词:Viruses; Metamorphic viruses; Signature based detectors
国家哲学社会科学文献中心版权所有