Analyzing Malware Based on Volatile Memory

Analyzing Malware Based on Volatile Memory
复制标题

基于易失性内存的恶意软件分析

DOI:
10.4304/jnw.8.11.2512-2519
复制
发表时间:
2013
期刊:
J. Networks
影响因子:
--
通讯作者:
Kuo Zhao
Kuo Zhao
中科院分区:
--
文献类型:
--
作者:
Liang Hu;Shinan Song;Xiaolu Zhang;Zhenzhen Xie;Xiangyu Meng;Kuo Zhao

文献摘要

相似文献

To explain the necessity of comprehensive and automatically analysis process for volatile memory, this paper summarized ordinarily analyzing methods and their common points especially for concerned data source. Then, a memory analysis framework Volatiltiy-2.2 and statistical output file size are recommended. In addition, to address the limitation of plug-ins classification in analyzing procedure, a user perspective classify is necessary and proposed. Furthermore, according to target data source differences on the base of result data set volume and employed relational method is introduced for comprehensive analysis guideline procedure. Finally, a test demo including DLLs loading order list analyzing is recommend, in which DLL load list is regard as different kind of characteristics typical data source with process and convert into process behavior fingerprint. The clustering for the fingerprint is employed string similar degree algorithm model in the demo, which has a wide range applications in traditional malware behavior analysis, and it is proposed that these methods also can be applied for volatile memory