Vui lòng dùng định danh này để trích dẫn hoặc liên kết đến tài liệu này: https://dspace.ctu.edu.vn/jspui/handle/123456789/119560
Nhan đề: Bypassing anti-emulation methods for malware detection
Tác giả: Cao, Van Loi
Nguyen, Dinh Dai
Từ khoá: Malware analysis
Malware detection
Obfuscation
Anti-emulation
Feature extraction
Năm xuất bản: 2024
Tùng thư/Số báo cáo: Journal of Computer Science and Cybernetics;Vol.40, No.03 .- P.233-248
Tóm tắt: Malware detection has played a crucial role in many cyberattacks in recent years. Due to the obfuscated nature of malware, the traditional static analysis technique tends to be ineffective. Additionally, modern malware often can identify dynamic analysis environments, posing challenges to dynamic analysis methods. Thus, feature extraction relies on analysis techniques that tend to be less effective in obfuscated malware, resulting in poor performance of subsequent machine learning-based detectors. This study introduces a Bypass Anti-emulation-based Malware Detection framework (BAE-MD) for enhancing the efficiency of obfuscated malware detection. In other words, BAE-MD includes a method that can bypass the anti-emulation mechanism of malware in a controlled dynamic environment. This forces the malware to decrypt and decompress its actual malicious code to memory. By doing so, Yara rules can be applied to memory dump to extract more than $60$ features to feed into detectors. BAE-MD is evaluated on a malware dataset in comparison with others using static and dynamic analysis technique-based feature extraction. The experimental results can confirm that our method outperforms the others. More investigations are also carried out to illustrate the efficiency of BAE-MD. These results suggest that BAE-MD is a promising approach for dealing with the continuous evolution of malware.
Định danh: https://dspace.ctu.edu.vn/jspui/handle/123456789/119560
ISSN: 1813-9663
Bộ sưu tập: Tin học và Điều khiển học (Journal of Computer Science and Cybernetics)

Các tập tin trong tài liệu này:
Tập tin Mô tả Kích thước Định dạng  
_file_
  Giới hạn truy cập
758.07 kBAdobe PDF
Your IP: 216.73.216.121


Khi sử dụng các tài liệu trong Thư viện số phải tuân thủ Luật bản quyền.