发新话题
打印

[转载]Polymorphic Worm Detection Using Structural Information of Executables

[转载]Polymorphic Worm Detection Using Structural Information of Executables

信息来源:邪恶八进制信息安全团队(www.eviloctal.com

This paper presents a novel technique based on the structural analysis of binary code that allows one to identify structural similarities between different worm mutations. The approach is based on the analysis of a worm’s control flow graph and introduces an original graph coloring technique that supports a more precise characterization of the worm’s structure. The technique has been used as a basis to implement a worm detection system that is resilient to many of the mechanisms used to evade approaches based on instruction sequences only.

附件

Polymorphic Worm Detection Using Structural Information of Executables.rar (218 KB)

2006-1-5 11:42, 下载次数: 53

曾几何时,有人对我说:装B遭雷劈。我说:去你妈的。于是,这个人又对我说:如果再说脏话,上帝会惩罚你的。我说:我操上帝。结论:彪悍的人生不需要上帝。

TOP

发新话题