Dissertation > Excellent graduate degree dissertation topics show

Research and Implementation of Critical Techniques in Malware Detection Based on Decompilation

Author: ZhangYiChi
Tutor: PangJianMin
School: PLA Information Engineering University
Course: Applied Computer Technology
Keywords: Malicious Codes Decompilation Detection Control Flow Obfuscation Identify Library Function
CLC: TP309
Type: Master's thesis
Year: 2009
Downloads: 78
Quote: 0
Read: Download Dissertation

Abstract


The broad spread of malware has presented a serious threat to the safety of computer systems. Many researchers are eager to develop a more practical and efficient detection technique to weaken the threat from malware. However, a great many of techniques, such as obfuscation, have been used by malware writers to evade current detection approaches. Reverse analysis based on decompilation is a technique to understand and analyze binary codes, by which the behavior of malware can be concluded through static analysis. It has superiority to detect the hidden threat of malware. So it is significant to investigate the malware detection based on decompilation.Based on the analysis and understanding of obfuscation technique used by malware, this thesis presents a deep study on the techniques and approaches adopted in decompilation to detect malware. First, according to the process of decompilation, classify the obfuscation used by malware into two types, pay more attention on two cases, i.e. junk insertion and subroutine exception return. Several approaches, such as virtual stack, re-decoding, control flow gap scan, are adopted to design and implement the disassemble frame and algorithms aiming at malware. Second, according to the analysis of assemble instruction sequence and the characteristics of the storages of library function name, a method to identify library function calling is proposed to deal with searching and loading library function dynamically by malware. After that, a malware detection approach based on sub-graph matching is introduced here, which identifies suspicious behavior in the executable and estimates the malicious degree through comparing control flow graph with malicious behavior defined in the malicious behavior library.The techniques and algorithms presented above have been applied to RADUX(Reverse Analysis for Detecting Unsafe eXecutables), a prototype for malware analysis and detection which is funded by the National High-Tech Research and Development Plan of China. The prototype is tested by two testing centers and used by an organization. Comparing the experimental data produced by RADUX with those by other common reverse analysis tools and famous antivirus(AV) tools, results show that the approaches introduced in this thesis, i.e., the disassemble algorithms, the methods to identify the library function and detection based on control flow graph, are favorable in their feasibility, efficiency and validity.

Related Dissertations

  1. Signal Detection Circuit Design for Slow-Light Optic Fiber Gyroscope,V241.5
  2. Realization of Fiber Optic Gyroscope Signal Processing Circuits Based on FPGA,V241.5
  3. Research on Automatic Detection Algorithm for Substructure Distress of Highway Pavement Based on SVM,U418.6
  4. Well Detection Pump Steady-Speed Driving System of Brushless DC Motor,TM33
  5. Study on the Echo Processing Method for the Measurement of Wire Length Based on Pulsereflection,TM247
  6. Research on Fault Detection and Network Reconfiguration Algorithms for Distribution Network,TM727
  7. The Matlab Implementation of Joint Source and Channel Decoding of Turbo Code Based on Meanmatch,TN911.22
  8. Research on Autamatic Music Structrue Analysis,TN912.3
  9. Research on 8 Mm-Band Direct Detection Radiometer,TN850.7
  10. Study of Target Simulation and Signal Processing Algorithm for Skywave Over-The-Horizon Radar,TN958.93
  11. Research of Image Mosaic Technology,TP391.41
  12. The Fatigue State Recognition of the Driver Based on Eye Detection,TP391.41
  13. Research on Joint Target Detection for Dual-Sensor Image and System Implementation,TP391.41
  14. Multi-currency Notes Technology Research and Implementation,TP391.41
  15. Camera Calibration and Position and Pose Detecting on Vision Measurement System of PCB,TP391.41
  16. The Research of Moving Object Tracking System Based on Embeded Image Process Unit,TP391.41
  17. Research of IRC Botnet Detection Based on Behavior,TP393.08
  18. Research on Visual Detection and Tracking of Mobile Robots,TP242.62
  19. Gradual Event Detection in Sensor Networks,TP212.9
  20. Implementation and Research of Illegal Websites Detection System Based on Comparison Methods,TP393.08
  21. Establish a Quantitative Method and Its Kit for Detection of Escherichia Coli and Salmonella. Spp,S154.3

CLC: > Industrial Technology > Automation technology,computer technology > Computing technology,computer technology > General issues > Security and confidentiality
© 2012 www.DissertationTopic.Net  Mobile