PE File Header Analysis-Based Packed PE File Detection Technique (PHAD)

PE File Header Analysis-Based Packed PE File Detection Technique (PHAD)
复制标题

基于PE文件头分析的加壳PE文件检测技术(PHAD)

DOI:
--
复制
发表时间:
2008
期刊:
International Symposium on Computer Science and its Applications
影响因子:
--
通讯作者:
Jaecheol Ryou
Jaecheol Ryou
中科院分区:
--
文献类型:
--
作者:
Yang;Ikkyun Kim;J. Oh;Jaecheol Ryou

文献摘要

被引文献

相似文献

为了隐藏恶意软件,恶意软件作者使用打包和加密技术。如果恶意软件被打包或加密,那么就很难分析。因此,为了防止恶意软件的有害影响,并生成用于恶意软件检测的签名,必须首先将打包和加密的可执行代码解压缩。解包的第一步是检测打包的可执行文件。本文提出了一种基于PE报头分析的压缩文件检测技术。在许多情况下,为了打包和解包可执行代码,PE文件在其PE头中具有不寻常的属性。在本文中,利用这些特征来检测打包文件。定义了由8个元素组成的特征向量,计算了特征向量的欧几里得距离。计算打包文件的EDs,并表示检测打包文件的基本阈值。
In order to conceal malware, malware authors use the packing and encryption techniques. If the malware is packed or encrypted, then it is very difficult to analyze. Therefore, to prevent the harmful effects of malware and to generate signatures for malware detection, the packed and encrypted executable codes must initially be unpacked. The first step of unpacking is to detect the packed executable files. In this paper, a packed file detection technique (PHAD) based on a PE header analysis is proposed. In many cases, to pack and unpack the executable codes, PE files have unusual attributes in their PE headers. In this paper, these characteristics are utilized to detect the packed files. a characteristic vector (CV) that consists of eight elements is defined, and the Euclidean distance (ED) of the CV is calculated. The EDs of the packed files are calculated and represent the base threshold for the detection of packed files.