Hierarchical Clustering Based Packed-Malware Categorization System

碩士 === 國立臺灣科技大學 === 資訊工程系 === 101 === Traditional antivirus technology determine malware by specific signatures, But the program once through parker and its contents have changed, Pattern recognition cannot recognize for it does or not. Therefore, The current malware often use software to packers, s...

Full description

Bibliographic Details
Main Authors: Chen Tsou, 鄒澄
Other Authors: Shi-Jinn Horng
Format: Others
Language:zh-TW
Published: 2013
Online Access:http://ndltd.ncl.edu.tw/handle/20777503378237672023
id ndltd-TW-101NTUS5392019
record_format oai_dc
spelling ndltd-TW-101NTUS53920192016-03-21T04:27:53Z http://ndltd.ncl.edu.tw/handle/20777503378237672023 Hierarchical Clustering Based Packed-Malware Categorization System 基於階層式分群法之加殼與病毒程式分類偵測系統 Chen Tsou 鄒澄 碩士 國立臺灣科技大學 資訊工程系 101 Traditional antivirus technology determine malware by specific signatures, But the program once through parker and its contents have changed, Pattern recognition cannot recognize for it does or not. Therefore, The current malware often use software to packers, so that it can effectively escape detection by antivirus software. The packer is actually using special algorithms to compress the file, but file can execute independently after compression. Because modern computer's CPU execution speed is very quickly, during Unpack process the user will not have the opportunity to understand what going on action program. How to identify whether a file is packed that becomes very important. Current general purpose tools PEiD has restrictions on its use. How to more effectively and quickly determine which file is packed. The current research focus on this field, and this paper presents using the sandbox environment to implement DLL detection files by API as a characteristic value. Agglomerative hierarchical clustering use these features to determine packers types and virus analysis. Shi-Jinn Horng 洪西進 2013 學位論文 ; thesis 86 zh-TW
collection NDLTD
language zh-TW
format Others
sources NDLTD
description 碩士 === 國立臺灣科技大學 === 資訊工程系 === 101 === Traditional antivirus technology determine malware by specific signatures, But the program once through parker and its contents have changed, Pattern recognition cannot recognize for it does or not. Therefore, The current malware often use software to packers, so that it can effectively escape detection by antivirus software. The packer is actually using special algorithms to compress the file, but file can execute independently after compression. Because modern computer's CPU execution speed is very quickly, during Unpack process the user will not have the opportunity to understand what going on action program. How to identify whether a file is packed that becomes very important. Current general purpose tools PEiD has restrictions on its use. How to more effectively and quickly determine which file is packed. The current research focus on this field, and this paper presents using the sandbox environment to implement DLL detection files by API as a characteristic value. Agglomerative hierarchical clustering use these features to determine packers types and virus analysis.
author2 Shi-Jinn Horng
author_facet Shi-Jinn Horng
Chen Tsou
鄒澄
author Chen Tsou
鄒澄
spellingShingle Chen Tsou
鄒澄
Hierarchical Clustering Based Packed-Malware Categorization System
author_sort Chen Tsou
title Hierarchical Clustering Based Packed-Malware Categorization System
title_short Hierarchical Clustering Based Packed-Malware Categorization System
title_full Hierarchical Clustering Based Packed-Malware Categorization System
title_fullStr Hierarchical Clustering Based Packed-Malware Categorization System
title_full_unstemmed Hierarchical Clustering Based Packed-Malware Categorization System
title_sort hierarchical clustering based packed-malware categorization system
publishDate 2013
url http://ndltd.ncl.edu.tw/handle/20777503378237672023
work_keys_str_mv AT chentsou hierarchicalclusteringbasedpackedmalwarecategorizationsystem
AT zōuchéng hierarchicalclusteringbasedpackedmalwarecategorizationsystem
AT chentsou jīyújiēcéngshìfēnqúnfǎzhījiākéyǔbìngdúchéngshìfēnlèizhēncèxìtǒng
AT zōuchéng jīyújiēcéngshìfēnqúnfǎzhījiākéyǔbìngdúchéngshìfēnlèizhēncèxìtǒng
_version_ 1718209599177228288