完整後設資料紀錄
DC 欄位語言
dc.contributor.authorLiu, Yen-Juen_US
dc.contributor.authorChen, Chong-Kuanen_US
dc.contributor.authorCho, Michael Cheng Yien_US
dc.contributor.authorShich, Shiuhpyngen_US
dc.date.accessioned2015-12-02T03:00:57Z-
dc.date.available2015-12-02T03:00:57Z-
dc.date.issued2014-01-01en_US
dc.identifier.isbn978-1-4799-4296-1en_US
dc.identifier.issn2378-3877en_US
dc.identifier.urihttp://dx.doi.org/10.1109/SERE.2014.33en_US
dc.identifier.urihttp://hdl.handle.net/11536/128598-
dc.description.abstractTo evade VM-based malware analysis systems, VM-aware malware equipped with the ability to detect the presence of virtual machine has appeared. To cope with the problem, detecting VM-aware malware and locating VM-sensitive divergence points of VM-aware malware is in urgent need. In this paper, we propose a novel block-based divergence locator. In contrast to the conventional instruction-based schemes, the block-based divergence locator divides malware program into basic blocks, instead of binary instructions, and uses them as the analysis unit. The block-based divergence locator significantly decrease the cost of behavior logging and trace comparison, as well as the size of behavior traces. As the evaluation showed, behavior logging is 23.87-39.49 times faster than the conventional schemes. The total number of analysis unit, which is highly related to the cost of trace comparisons, is 11.95%-16.00% of the conventional schemes. Consequently, VM-sensitive divergence points can be discovered more efficiently. The correctness of our divergence point discovery algorithm is also proved formally in this paper.en_US
dc.language.isoen_USen_US
dc.subjectMalware Behavior Analysisen_US
dc.subjectVM-Aware Malwareen_US
dc.subjectVirtual Machineen_US
dc.titleFast Discovery of VM-Sensitive Divergence Points with Basic Block Comparisonen_US
dc.typeProceedings Paperen_US
dc.identifier.doi10.1109/SERE.2014.33en_US
dc.identifier.journal2014 EIGHTH INTERNATIONAL CONFERENCE ON SOFTWARE SECURITY AND RELIABILITYen_US
dc.citation.spage196en_US
dc.citation.epage205en_US
dc.contributor.department資訊工程學系zh_TW
dc.contributor.departmentDepartment of Computer Scienceen_US
dc.identifier.wosnumberWOS:000360819100021en_US
dc.citation.woscount0en_US
顯示於類別:會議論文