Dissertation > Excellent graduate degree dissertation topics show

Detection and Analysis of Malware Network Behavior Based on Isolation Environment

Author: WuYiLun
Tutor: LuXiCheng
School: National University of Defense Science and Technology
Course: Computer Science and Technology
Keywords: Malware Dynamic Analysis Dynamic taint analysis Message Semantic Analysis
CLC: TP393.08
Type: Master's thesis
Year: 2011
Downloads: 19
Quote: 0
Read: Download Dissertation

Abstract


In the field of computer security, malware has been are important threat. Malware to cause serious damage to the computer through the destruction of the operating environment, tampering file data. With the continuous development of network technology, the malicious software continue to strengthen the ability of self-propagating through the network, which presented a new challenge for computer protection outside malware intrusion. In this paper, the principle of dynamic analysis of malware behavior monitoring and analysis, focusing on the network behavior of malware research. Through the monitoring and analysis of malware behavior, found that the mode of implementation of the special behavior of malware, and to contain malware spreads itself via the Internet to provide technical reference. The main work of this paper include the following four aspects: This article is based on dynamic analysis techniques to achieve dynamic monitoring mechanism and hijacking mechanism. Dynamic monitoring mechanism, the behavior of the malware is successfully captured. Hijacking mechanism to obtain important information for detailed descriptions of the behavioral characteristics. Acquisition, became the basis of the analysis of the network behavior of malware behavior for malicious software. In this paper, the message semantic parsing using dynamic taint analysis and malware behavior. Through dynamic stain analysis, to trace malicious software behavior the flow of information in memory, and resolve the semantics of the messages generated in the network. The message semantic parsing can for observation messages constitute for monitoring malware spread prerequisites. Against malicious software, self-replicating and self-propagation characteristics were analyzed. The self-replicating malware, malware behavior sequence, a self-replicating malware identification mechanism. Self-propagating malicious software, combined with malware behavior sequence as well as the message semantic parsing, to identify the mechanism of self-propagating malware. This design and to achieve a malware network behavior based on the isolation environment monitoring and analysis system TermiNetor. The system can track the behavior of malware in the isolated environment. TermiNetor system to achieve all of the above proposed methods and mechanisms, analysis of network behavior of malware, and clearly self-replicating malware behavior and self-propagation behavior.

Related Dissertations

  1. The Research of Malware Detection Technology Based on Active Mode,TP393.08
  2. The Study of Dynamic Simulation of the Passive Dynamic Quasi-Quarupedal Walker,TP242.6
  3. The Effectr of Lactic Acid Bacteria and Rice Bran on Dynamic Change of Rice Straw Silage Fermentation,S816.53
  4. Isolationand Identification of Porcine Parvovirus and Parts of Its Biological Characteristics,S852.65
  5. Study of Static and Dynamic Collaborative Optimization on Container Ship Structure,U674.131
  6. Study on Mechanical Characteristic of Rubber Spring Used in Vibrating Screen,O322
  7. Reliability-based Sensitivity Research on Multi-span Rotor System,TH113
  8. Research on Botnet Traffic Detection Based on Spatial-temporal Correlation Analysis,TP393.08
  9. A Static Behavior-Based Method to Detect Malware on Android,TP309
  10. Dynamic analysis based on multi-core acceleration method,TP332
  11. Deep-sea umbilicals dynamic response and reliability of bending enhancer,P756.1
  12. AVIC International Plaza Building, structural stability analysis,TU973.2
  13. Magnet contactor design and analysis of static and dynamic characteristics,TM572.1
  14. Seismic Response Analysis of Continuous Frame Bridge with V Piers,U441.3
  15. Dynamic Analysis of Soils under Moving Load,TU435
  16. Research on the Square RAM Deformation Processing and Compensation,TG548
  17. Large capacity long distance belt conveyor Dynamic Characteristics,TD528.1
  18. The Structural Design and Experimental Research on Kilometer Pitch Carbon Fiber Roll-up System,TQ342.742
  19. Semi-analytical Analysis of Super Tall Building Bundled Tube Structures Due to Deterministic Dynamic Loadings,TU973.17
  20. The Structural Influencing Coefficient of Steel Frames in Different Site,TU391

CLC: > Industrial Technology > Automation technology,computer technology > Computing technology,computer technology > Computer applications > Computer network > General issues > Computer Network Security
© 2012 www.DissertationTopic.Net  Mobile