Successive memory image analysis method for malicious codes

Autor: Wei-ming LI, De-qing ZOU, Guo-zhong SUN
Jazyk: English<br />Chinese
Rok vydání: 2017
Předmět:
Zdroj: 网络与信息安全学报, Vol 3, Pp 20-30 (2017)
Druh dokumentu: article
ISSN: 2096-109X
DOI: 10.11959/j.issn.2096-109x.2017.00144
Popis: In order to detect the behavior of malicious code more comprehensively, the technology of continuous memory image analysis was proposed. The core idea was to run malicious code in QEMU virtual machine, to obtain the memory image of the continuous increment in the running period, and then to analyze the memory image of the base and increment as the memory image. On the basis of the analysis of a single memory image, different memory images were analysised comparatively. At the same time, the visualization tool D3.js was used to visually display the change of the memory state in the process of system operation. Finally, the prototype system was tested by 40 kinds of malicious code samples, and the number of malicious code behavior was increased by 19.7% than traditional sin-gle memory image.
Databáze: Directory of Open Access Journals