+Advanced Search

Obfuscated Malicious Code Detection with Path Condition Analysis
Author:
Affiliation:

Fund Project:

  • Article
  • |
  • Figures
  • |
  • Metrics
  • |
  • Reference
  • |
  • Related
  • |
  • Cited by
  • |
  • Materials
    Abstract:

    Codes obfuscation is one of the main methods to hide malicious codes. This paper proposed a new dynamic method to effectively detect obfuscated malicious codes. This method used ISR to conduct dynamic debugging. The constraint solving during the debugging process can detect deeply hidden malicious codes by covering different execution paths. Besides, for malicious codes that read external resources, the detection of abnormal behaviors can only be detected by taking the resources into consideration. The method proposed has better accuracy by locating the external resources precisely and combining it with the analysis of original malicious codes. According to the test result of 12 anti-virus softwares, this prototype system can noticeably decrease False Negatives rate in the detection of obfuscated malicious codes.

    Reference
    Related
    Cited by
Article Metrics
  • PDF:
  • HTML:
  • Abstract:
  • Cited by:
Get Citation
History
  • Received:
  • Revised:
  • Adopted:
  • Online:
  • Published: