完整後設資料紀錄
| DC 欄位 | 值 | 語言 |
|---|---|---|
| dc.contributor.author | Liu, Yen-Ju | en_US |
| dc.contributor.author | Chen, Chong-Kuan | en_US |
| dc.contributor.author | Cho, Michael Cheng Yi | en_US |
| dc.contributor.author | Shich, Shiuhpyng | en_US |
| dc.date.accessioned | 2015-12-02T03:00:57Z | - |
| dc.date.available | 2015-12-02T03:00:57Z | - |
| dc.date.issued | 2014-01-01 | en_US |
| dc.identifier.isbn | 978-1-4799-4296-1 | en_US |
| dc.identifier.issn | 2378-3877 | en_US |
| dc.identifier.uri | http://dx.doi.org/10.1109/SERE.2014.33 | en_US |
| dc.identifier.uri | http://hdl.handle.net/11536/128598 | - |
| dc.description.abstract | To evade VM-based malware analysis systems, VM-aware malware equipped with the ability to detect the presence of virtual machine has appeared. To cope with the problem, detecting VM-aware malware and locating VM-sensitive divergence points of VM-aware malware is in urgent need. In this paper, we propose a novel block-based divergence locator. In contrast to the conventional instruction-based schemes, the block-based divergence locator divides malware program into basic blocks, instead of binary instructions, and uses them as the analysis unit. The block-based divergence locator significantly decrease the cost of behavior logging and trace comparison, as well as the size of behavior traces. As the evaluation showed, behavior logging is 23.87-39.49 times faster than the conventional schemes. The total number of analysis unit, which is highly related to the cost of trace comparisons, is 11.95%-16.00% of the conventional schemes. Consequently, VM-sensitive divergence points can be discovered more efficiently. The correctness of our divergence point discovery algorithm is also proved formally in this paper. | en_US |
| dc.language.iso | en_US | en_US |
| dc.subject | Malware Behavior Analysis | en_US |
| dc.subject | VM-Aware Malware | en_US |
| dc.subject | Virtual Machine | en_US |
| dc.title | Fast Discovery of VM-Sensitive Divergence Points with Basic Block Comparison | en_US |
| dc.type | Proceedings Paper | en_US |
| dc.identifier.doi | 10.1109/SERE.2014.33 | en_US |
| dc.identifier.journal | 2014 EIGHTH INTERNATIONAL CONFERENCE ON SOFTWARE SECURITY AND RELIABILITY | en_US |
| dc.citation.spage | 196 | en_US |
| dc.citation.epage | 205 | en_US |
| dc.contributor.department | 資訊工程學系 | zh_TW |
| dc.contributor.department | Department of Computer Science | en_US |
| dc.identifier.wosnumber | WOS:000360819100021 | en_US |
| dc.citation.woscount | 0 | en_US |
| 顯示於類別: | 會議論文 | |

