作者: Scott Treadwell , Mian Zhou
关键词:
摘要: Obfuscated malware has become popular because of pure benefits brought by obfuscation: low cost and readily availability obfuscation tools accompanied with good result evading signature based anti-virus detection as well prevention reverse engineer from understanding malwares' true nature. Regardless methods, a must deobfuscate its core code back to clear executable machine so that malicious portion will be executed. Thus, analyze the pattern before unpacking provide chance for us prevent further execution. In this paper, we propose heuristic approach targets obfuscated windows binary files being loaded into memory - prior We perform series static check on file's PE structure common traces packer or obfuscation, gauge binary's maliciousness simple risk rating mechanism. As result, newly created process, if flagged possibly screening, prevented This paper explores foundation research, testing methodology current results.