>
Fa   |   Ar   |   En
   DyVSoR: Dynamic Malware Detection Based on Extracting Patterns from Value Sets of Registers  
   
نویسنده Ghiasi Mahboobe ,Sami Ashkan ,Salehi Zahra
منبع the isc international journal of information security - 2013 - دوره : 5 - شماره : 1 - صفحه:71 -82
چکیده    To control the exponential growth of malware files, security analysts pursue dynamic approaches that automatically identify and analyze malicious software samples. obfuscation and polymorphism employed by malwares make it difficult for signature-based systems to detect sophisticated malware files. the dynamic analysis or run-time behavior provides a better technique to identify the threat. in this paper, a dynamic approach is proposed in order to extract features from binaries. the run-time behavior of the binary files were found and recorded using a homemade tool that provides a controlled environment. the approach based on dyvsor assumes that the run-time behavior of each binary can be represented by the values of registers. a method to compute the similarity between two binaries based on the value sets of the registers is presented. hence, the values are traced before and after invoked api calls in each binary and mapped to some vectors. to detect an unknown file, it is enough to compare it with dataset binaries by computing the distance between registers, content of this file and all binaries. this method could detect malicious samples with 96.1% accuracy and 4% false positive rate. the list of execution traces and the dataset are reachable at: http://home.shirazu.ac.ir/~ sami/malware
کلیدواژه Malware Detection ,API Call ,Dynamic Analysis ,CPU Register Values ,x86 Registers Values.
آدرس shiraz university, Computer Science and Engineering and Information Technology Department, ایران, shiraz university, Computer Science and Engineering and Information Technology Department, ایران, shiraz university, Computer Science and Engineering and Information Technology Department, ایران
پست الکترونیکی zsalehi@cse.shirazu.ac.ir
 
     
   
Authors
  
 
 

Copyright 2023
Islamic World Science Citation Center
All Rights Reserved