Detection of packed executables using support vector machines

Detection of packed executables using support vector machines
复制标题

使用支持向量机检测打包的可执行文件

DOI:
--
复制
发表时间:
2011
期刊:
International Conference on Machine Learning and Computing
影响因子:
--
通讯作者:
C. Wu
C. Wu
中科院分区:
--
文献类型:
--
作者:
Tzu;C. Wu

文献摘要

被引文献

相似文献

可执行封隔器是一种软件保护工具,最初是为了将重要程序的信息打包,防止恶意逆向工程而设计的。然而,打包也成为恶意软件界流行的代码混淆手段之一。使用压缩和加密策略,打包者能够改变恶意软件的外观,以混淆模式匹配和启发式分析等检测机制。因此,本文提出了一个通用的包装检测框架(PDF)。这个框架首先静态地检查每个可执行文件的可移植可执行文件,以收集一组与可执行文件相关的原始属性。在运行PDF提供的后续属性细化过程后,提取有值属性,然后用于训练两类支持向量机器学习分类器来识别可执行文件是否被打包。通过对1,056个未打包的可执行文件和3,784个打包的可执行文件进行评估,结果表明我们的PDF在打包检测方面很有希望。
Executable packer is a kind of software protecting tools originally designed to pack the information of important programs against malicious reverse engineering. However, packing has also become one of the code obfuscation means prevailing among malware society. Using compression and encryption tactics, packers are able to alter the appearance of malware to confuse detection mechanisms such as pattern matching and heuristics analysis. Therefore, a generic packing detection framework (PDF) is proposed in this study. This framework first statically examines the Portable Executable (PE) file of each executable to gather a set of executable-related raw attributes. After running a subsequent attribute refinement process provided by PDF, valued attributes are extracted and then used to train a two-class support vector machines learning classifier to recognize whether a executable is packed. By evaluating on 1,056 non-packed and 3,784 packed executables, the resulting performances demonstrated that our PDF is promising in packing detection.