Executable Code Recognition in Network Flows Using Instruction Transition Probabilities
スポンサーリンク
概要
- 論文の詳細を見る
The ability to recognize quickly inside network flows to be executable is prerequisite for malware detection. For this purpose, we introduce an instruction transition probability matrix (ITPX) which is comprised of the IA-32 instruction sets and reveals the characteristics of executable codes instruction transition patterns. And then, we propose a simple algorithm to detect executable code inside network flows using a reference ITPX which is learned from the known Windows Portable Executable files. We have tested the algorithm with more than thousands of executable and non-executable codes. The results show that it is very promising enough to use in real world.
- (社)電子情報通信学会の論文
- 2008-07-01
著者
-
JANG Jongsoo
Electronics and Telecommunications Research Institute (ETRI)
-
KIM Daewon
Information Security Research Division, Electronics and Telecommunications Research Institute
-
KIM Ikkyun
Information Security Research Division, Electronics and Telecommunications Research Institute
-
OH Jintae
Information Security Research Division, Electronics and Telecommunications Research Institute
-
JANG Jongsoo
Information Security Research Division, Electronics and Telecommunications Research Institute
-
KANG Koohong
Dept. of Information and Communications Engineering, Seowon University
-
CHOI Yangseo
Information Security Research Division, ETRI
-
HAN Kijun
Dept. of Computer Engineering, Kyungpook National University
-
Oh Jintae
Information Security Research Division Etri
-
Han Kijun
Dept. Of Computer Engineering Kyungpook National University
-
Kim Daewon
Information Security Research Division Etri
-
Choi Yangseo
Information Security Research Division Etri
-
Kim Ikkyun
Information Security Research Division Etri
-
Kang Koohong
Dept. Of Information And Communications Engineering Seowon University
関連論文
- Random Visitor : Defense against Identity Attacks in P2P Networks
- Tracing Stored Program Counter to Detect Polymorphic Shellcode
- Executable Code Recognition in Network Flows Using Instruction Transition Probabilities