| 注册
首页|期刊导航|重庆大学学报:自然科学版|恶意代码的符号执行树分析方法

恶意代码的符号执行树分析方法

钟金鑫 魏更宇 安靖 杨义先

重庆大学学报:自然科学版2012,Vol.35Issue(2):65-70,6.
重庆大学学报:自然科学版2012,Vol.35Issue(2):65-70,6.

恶意代码的符号执行树分析方法

A malware analysis method based on symbolic execution tree

钟金鑫 1魏更宇 1安靖 1杨义先1

作者信息

  • 1. 北京邮电大学信息安全中心,北京100876
  • 折叠

摘要

Abstract

In the malware analysis, it is a common method to monitor malware dynamically in a virtual environment. However, with so many branches of executable pathes, path explosion problem will probably occur, leaving some executable pathes uncovered, and hence harming the comprehensiveness of analysis. To solve this problem, we propose a rnalware analysis method based on symbolic execution tree. This method introduces sinknode and solves the execution of malicious code path by constructing the symbolic execution tree, so improves the analysis of comprehensive. Experiments to analyze the samples of malware show that the method can enhance the efficiency of the analysis with lower time complexity.

关键词

符号执行/路径爆炸/恶意代码分析/汇聚节点/二进制程序分析

Key words

symbolic execution/path explosion/malware analysis/sink node/binary analysis

分类

信息技术与安全科学

引用本文复制引用

钟金鑫,魏更宇,安靖,杨义先..恶意代码的符号执行树分析方法[J].重庆大学学报:自然科学版,2012,35(2):65-70,6.

基金项目

国家自然科学基金资助项目 ()

重庆大学学报:自然科学版

OA北大核心CSCDCSTPCD

1000-582X

访问量0
|
下载量0
段落导航相关论文