作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2008, Vol. 34 ›› Issue (5): 169-170,. doi: 10.3969/j.issn.1000-3428.2008.05.059

• 安全技术 • 上一篇    下一篇

基于归一化的变形恶意代码检测

金 然,魏 强,王清贤   

  1. (信息工程大学信息工程学院,郑州 450002)
  • 收稿日期:1900-01-01 修回日期:1900-01-01 出版日期:2008-03-05 发布日期:2008-03-05

Metamorphic Malware Detection Based on Normalization

JIN Ran, WEI Qiang, WANG Qing-xian   

  1. (Information Engineering Institute, Information Engineering University, Zhengzhou 450002)
  • Received:1900-01-01 Revised:1900-01-01 Online:2008-03-05 Published:2008-03-05

摘要: 许多未知恶意代码是由已知恶意代码变形而来。该文针对恶意代码常用的变形技术,包括等价指令替换、插入垃圾代码和指令重排,提出完整的归一化方案,以典型的变形病毒Win32.Evol对原型系统进行测试,是采用归一化思想检测变形恶意代码方面的有益尝试。

关键词: 变形恶意代码, 归一化, 恶意代码检测

Abstract: Much of unknown malware comes from transformed known malware. This paper proposes a complete normalization scheme to resolve the common transforming methods, including identical instructions substitution, garbage code insertion and code reordering. It implements a prototype system and a test to the system is conducted using Win32.Evol, a typical metamorphic virus. It makes a useful attempt to adopt normalization to detect metamorphic malware.

Key words: metamorphic malware, normalization, malware detection

中图分类号: