WANG Rui, SU Pu-rui, YANG Yi, et al. An Anti-obfuscation Malware Variants Identification System[J]. Acta Electronica Sinica, 2011, 39(10): 2322-2330.
DOI:
WANG Rui, SU Pu-rui, YANG Yi, et al. An Anti-obfuscation Malware Variants Identification System[J]. Acta Electronica Sinica, 2011, 39(10): 2322-2330.DOI:
An Anti-obfuscation Malware Variants Identification System
Malware variants are one of the major challenges in malware detecting today.Obfuscation
as a most popular technology to generate these variants
can change the signatures of malware to avoid the current signature-based malware preventing method
which is a big threat to information system.This paper proposes a novel anti-obfuscate malware detecting method.By making use of dynamic taint analysis methods and trigger-based behavior processing engine
this method can abstract the essential behavior logic of malware in fine-grained and form it as signatures of a class of malware
and identify variants more precisely associated with signature merging optimizing process and fuzzy matching methods.Experiment results show that the detecting method in this paper can identify malwares and its variants efficiently.