arrow
返回

Exploiting an antivirus interface

delete2009-11-01
delete27
delete
OA
AI
K
Kevin W. Hamlen *
V
Vishwath Mohan
M
Mohammad Mehedy Masud
L
Latifur Khan
B
Bhavani Thuraisingham
DOI:10.1016/j.csi.2009.04.004delete
delete原文链接
delete分享
delete收藏
查看原文
摘要

摘要

En 中文
We propose a technique for defeating signature-based malware detectors by exploiting information disclosed by antivirus interfaces. This information is leveraged to reverse engineer relevant details of the detector's underlying signature database, revealing binary obfuscations that suffice to conceal malware from the detector. Experiments with real malware and antivirus interfaces on Windows operating systems justify the effectiveness of our approach. (C) 2009 Elsevier B.V. All rights reserved.
Keyword:
Security
Signature-based malware detection
Data mining
Binary obfuscation
AI总结

AI总结

对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。

期刊

C
Computer Standards and Interfaces
IF:
3.1
论文数:
2.3K
被引数:
2.0K

机构

U
university of texas system
学者数:
18.5W
论文数: 15.6W
被引数: 210
引用论文

引用论文

Computer virus - Coevolution
err1997-01-01
err108
errOAAI
errNachenberg, C
err分享
err收藏
Support-vector networks支持向量网络
err1995-09-01
err0
errOAAI
errCorinna Cortes; Vladimir Vapnik
err分享
err收藏
A scalable multi-level feature extraction technique to detect malicious executables
err2007-10-23
err61
PREAI
errMasud, Mohammad M.; Khan, Latifur; Thuraisingham, Bhavani
err分享
err收藏