作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2007, Vol. 33 ›› Issue (12): 154-156. doi: 10.3969/j.issn.1000-3428.2007.12.054

• 安全技术 • 上一篇    下一篇

恶意代码模糊变换技术研究

庞立会,胡华平   

  1. (国防科技大学计算机学院,长沙 410073)
  • 收稿日期:1900-01-01 修回日期:1900-01-01 出版日期:2007-06-20 发布日期:2007-06-20

Research on Obfuscating Transformation Technology for Malicious Code

PANG Lihui, HU Huaping   

  1. (School of Computer Science, National University of Defense Technology, Changsha 410073)
  • Received:1900-01-01 Revised:1900-01-01 Online:2007-06-20 Published:2007-06-20

摘要: 在分析恶意代码模糊变换技术的基础上,给出了恶意代码模糊变换的形式化描述,提出了模糊变换引擎的框架结构,实现了恶意代码模糊变换引擎原型。试验结果表明模糊变换技术可以有效地提高恶意代码的生存能力。

关键词: 恶意代码, 特征码扫描, 模糊变换, 变形

Abstract: Based on the analysis of the obfuscating transformation technology used by malicious code, this paper formally specifies the obfuscating transformation, presents a framework of obfuscating transformation engine, and develops a prototype. The experiment results show that obfuscating transformation can be used to improve the survivability of the malicious code.

Key words: Malicious code, Signature scanning, Obfuscating transformation, Metamorphism

中图分类号: