earticle

논문검색

Encoded Executable File Detection Technique via Executable File Header Analysis

초록

영어

Recently, the attack trends have been changed from fast and widespread malware propagation attacks to more sophisticated “targeted” attacks such as spy/adware, password stealers, ransom-ware, and botenets etc. and the attacks are tried via the automated malwares. In this situation, the malware is the most powerful weapon for the attackers. So, the attackers do not want their malwares to be reviled by anti-virus analyzer. In order to conceal their malware, malware programmers are getting utilize the anti reverse engineering techniques and code changing techniques such as the packing, encoding and encryption techniques. If the malware is packed or encrypted, then it is very difficult to analyze. Therefore, to prevent the harmful effects of malware and to generate signatures for malware detection, the packed and encrypted executable codes must initially be unpacked. The first step of unpacking is to detect the packed executable files. In this paper, a packed file detection technique based on a PE Header Analysis is proposed. In many cases, to pack and unpack the executable codes, PE files have unusual attributes in their PE headers. In this paper, these characteristics are utilized to detect the packed files. A Characteristic Vector (CV) that consists of eight elements is defined, and the Euclidean distance (ED) of the CV is calculated. The EDs of the packed files are calculated and represent the base threshold for the detection of packed files.

목차

Abstract
 1. Introduction
 2. Related Works
  2.1. Using entropy analysis to find encrypted and packed malware [9]
  2.2. PEiD[10]
  2.3. Ollydbg[11]
  2.4. Exeinfo PE[45]
 3. PE file format
 4. PE Header Analysis-based packed file Detection
  4.1. Characteristic vectors
  4.2. Euclidean distance
 5. Experimental results
 6. Conclusions and future works
 References

저자정보

  • Yang-seo Choi ETRI Secure Gateway System Team
  • Ik-kyun Kim ETRI Secure Gateway System Team
  • Jin-tae Oh ETRI Secure Gateway System Team
  • Jae-cheol Ryou Dept. of Computer-Engineering Chung-Nam National University

참고문헌

자료제공 : 네이버학술정보

    함께 이용한 논문

      ※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

      0개의 논문이 장바구니에 담겼습니다.