Hierarchical Clustering Based Packed-Malware Categorization System
碩士 === 國立臺灣科技大學 === 資訊工程系 === 101 === Traditional antivirus technology determine malware by specific signatures, But the program once through parker and its contents have changed, Pattern recognition cannot recognize for it does or not. Therefore, The current malware often use software to packers, s...
Main Authors: | , |
---|---|
Other Authors: | |
Format: | Others |
Language: | zh-TW |
Published: |
2013
|
Online Access: | http://ndltd.ncl.edu.tw/handle/20777503378237672023 |
id |
ndltd-TW-101NTUS5392019 |
---|---|
record_format |
oai_dc |
spelling |
ndltd-TW-101NTUS53920192016-03-21T04:27:53Z http://ndltd.ncl.edu.tw/handle/20777503378237672023 Hierarchical Clustering Based Packed-Malware Categorization System 基於階層式分群法之加殼與病毒程式分類偵測系統 Chen Tsou 鄒澄 碩士 國立臺灣科技大學 資訊工程系 101 Traditional antivirus technology determine malware by specific signatures, But the program once through parker and its contents have changed, Pattern recognition cannot recognize for it does or not. Therefore, The current malware often use software to packers, so that it can effectively escape detection by antivirus software. The packer is actually using special algorithms to compress the file, but file can execute independently after compression. Because modern computer's CPU execution speed is very quickly, during Unpack process the user will not have the opportunity to understand what going on action program. How to identify whether a file is packed that becomes very important. Current general purpose tools PEiD has restrictions on its use. How to more effectively and quickly determine which file is packed. The current research focus on this field, and this paper presents using the sandbox environment to implement DLL detection files by API as a characteristic value. Agglomerative hierarchical clustering use these features to determine packers types and virus analysis. Shi-Jinn Horng 洪西進 2013 學位論文 ; thesis 86 zh-TW |
collection |
NDLTD |
language |
zh-TW |
format |
Others
|
sources |
NDLTD |
description |
碩士 === 國立臺灣科技大學 === 資訊工程系 === 101 === Traditional antivirus technology determine malware by specific signatures, But the program once through parker and its contents have changed, Pattern recognition cannot recognize for it does or not. Therefore, The current malware often use software to packers, so that it can effectively escape detection by antivirus software. The packer is actually using special algorithms to compress the file, but file can execute independently after compression. Because modern computer's CPU execution speed is very quickly, during Unpack process the user will not have the opportunity to understand what going on action program. How to identify whether a file is packed that becomes very important. Current general purpose tools PEiD has restrictions on its use. How to more effectively and quickly determine which file is packed. The current research focus on this field, and this paper presents using the sandbox environment to implement DLL detection files by API as a characteristic value. Agglomerative hierarchical clustering use these features to determine packers types and virus analysis.
|
author2 |
Shi-Jinn Horng |
author_facet |
Shi-Jinn Horng Chen Tsou 鄒澄 |
author |
Chen Tsou 鄒澄 |
spellingShingle |
Chen Tsou 鄒澄 Hierarchical Clustering Based Packed-Malware Categorization System |
author_sort |
Chen Tsou |
title |
Hierarchical Clustering Based Packed-Malware Categorization System |
title_short |
Hierarchical Clustering Based Packed-Malware Categorization System |
title_full |
Hierarchical Clustering Based Packed-Malware Categorization System |
title_fullStr |
Hierarchical Clustering Based Packed-Malware Categorization System |
title_full_unstemmed |
Hierarchical Clustering Based Packed-Malware Categorization System |
title_sort |
hierarchical clustering based packed-malware categorization system |
publishDate |
2013 |
url |
http://ndltd.ncl.edu.tw/handle/20777503378237672023 |
work_keys_str_mv |
AT chentsou hierarchicalclusteringbasedpackedmalwarecategorizationsystem AT zōuchéng hierarchicalclusteringbasedpackedmalwarecategorizationsystem AT chentsou jīyújiēcéngshìfēnqúnfǎzhījiākéyǔbìngdúchéngshìfēnlèizhēncèxìtǒng AT zōuchéng jīyújiēcéngshìfēnqúnfǎzhījiākéyǔbìngdúchéngshìfēnlèizhēncèxìtǒng |
_version_ |
1718209599177228288 |