상세 보기
문자열과 API를 이용한 악성코드 자동 분류 시스템
- 박재우;
- 문성태;
- 손기욱;
- 한경수;
- 김인경;
- ... 임을규;
- 외 1명
초록
Recently, various malicious programs are being produced and distributed causing problems in networks; such as infecting user computers, exposing personal information including finance information, IDs, and passwords that are stored in computers, and attacking infected computers by DDoS attacks, etc. In addition, variant malicious programs are easily created with widely spread automatic tools and are expected to increase geometrically.However, detection methods that use former signatures are not easily applied to variant programs and the countermeasures to detect these variant malicious programs such as updating databases, etc. cannot cope with the rapidly growing number of mutated malicious software. Therefore, countermeasures and analysis are required to block the spreading of these malicious programs of the same kind or variant ones. This thesis suggests a method for classifying same or variant types of malicious programs through analyzing the binary execution file and actions of malicious programs and actually classifies and explains the results of the suggested method on malicious program samples.
키워드
- 제목
- 문자열과 API를 이용한 악성코드 자동 분류 시스템
- 제목 (타언어)
- An Automatic Malware Classification System using String List and APIs
- 저자
- 박재우; 문성태; 손기욱; 한경수; 김인경; 임을규; 김일곤
- 발행일
- 2011-10
- 저널명
- 보안공학연구논문지
- 권
- 8
- 호
- 5
- 페이지
- 611 ~ 626