نوع مقاله : مقاله پژوهشی
نویسندگان
1 دانشگاه آزاد شبستر
2 علم و صنعت ایران
چکیده
کلیدواژهها
عنوان مقاله [English]
In this article a new technique is proposed for detection of polymorphic malware based on image processing. With the proliferation of polymorphic malware, the efficacy of signature-based static analysis systems is greatly reduced. This survey is based on the comparison of the images developed from malware samples binary code. With the advent of image processing applications for binary code analysis, numerous features could be extracted for comparing malware isomorphs. Based on these features, we have been capable of detecting malware isomporphs with an unprecedented accuracy. Most often, malware samples binaries are packed. Using our proposed method, we have been capable of detecting the unique similarity between executables packed with a same packer.
کلیدواژهها [English]