Classification of packed executables for accurate computer virus detection

Classification of packed executables for accurate computer virus detection
复制标题

DOI:
10.1016/j.patrec.2008.06.016
复制
发表时间:
2008-10
期刊:
Pattern Recognit. Lett.
影响因子:
--
通讯作者:
R. Perdisci;A. Lanzi;Wenke Lee
R. Perdisci;A. Lanzi;Wenke Lee
中科院分区:
其他
文献类型:
--
作者:
R. Perdisci;A. Lanzi;Wenke Lee

文献摘要

被引文献

相似文献

可执行文件打包是计算机病毒编写者用来混淆恶意代码和躲避反病毒软件检测的最常见技术。已经提出了通用解包器,可以从打包的可执行文件中检测和提取加密代码,因此可能会揭示隐藏的病毒,然后可以通过传统的基于签名的反病毒软件来检测这些病毒。然而,通用解包器的计算成本很高,扫描大量的可执行文件集合以寻找病毒感染可能需要几个小时甚至几天的时间。在本文中,我们应用模式识别技术来快速检测打包的可执行文件。其目的是高效和准确地区分打包和非打包的可执行文件,以便只有被检测为打包的可执行文件才会被发送到通用解包器,从而节省大量的处理时间。实验结果表明,该系统能够以较低的平均处理时间获得很高的压缩可执行文件检测准确率。
Executable packing is the most common technique used by computer virus writers to obfuscate malicious code and evade detection by anti-virus software. Universal unpackers have been proposed that can detect and extract encrypted code from packed executables, therefore potentially revealing hidden viruses that can then be detected by traditional signature-based anti-virus software. However, universal unpackers are computationally expensive and scanning large collections of executables looking for virus infections may take several hours or even days. In this paper we apply pattern recognition techniques for fast detection of packed executables. The objective is to efficiently and accurately distinguish between packed and non-packed executables, so that only executables detected as packed will be sent to an universal unpacker, thus saving a significant amount of processing time. We show that our system achieves very high detection accuracy of packed executables with a low average processing time.