Proceedings of the International Conference on Advances in Mechanical Engineering and Industrial Informatics

A Malware Behavior Analysis Method based on Coupling Degree

Authors
Gang Guo, Sheng-jun Wei
Corresponding Author
Gang Guo
Available Online April 2015.
DOI
10.2991/ameii-15.2015.109How to use a DOI?
Keywords
obfuscation technique; Data fusion; coupling degree
Abstract

Aiming at the malware obfuscation technique, a new software behavior analysis method is proposed in the paper. The instruction coupling degree is calculated through mapping and associating the code analysis and log analysis to judge whether the instructions belong to the same behavior and then obtain the instruction information and operation process of different behaviors. The experiment proves that the method can effectively avoid the interference caused by the obfuscation techniques with the characteristics of good fault tolerance and high analysis accuracy.

Copyright
© 2015, the Authors. Published by Atlantis Press.
Open Access
This is an open access article distributed under the CC BY-NC license (http://creativecommons.org/licenses/by-nc/4.0/).

Download article (PDF)

Volume Title
Proceedings of the International Conference on Advances in Mechanical Engineering and Industrial Informatics
Series
Advances in Engineering Research
Publication Date
April 2015
ISBN
10.2991/ameii-15.2015.109
ISSN
2352-5401
DOI
10.2991/ameii-15.2015.109How to use a DOI?
Copyright
© 2015, the Authors. Published by Atlantis Press.
Open Access
This is an open access article distributed under the CC BY-NC license (http://creativecommons.org/licenses/by-nc/4.0/).

Cite this article

TY  - CONF
AU  - Gang Guo
AU  - Sheng-jun Wei
PY  - 2015/04
DA  - 2015/04
TI  - A Malware Behavior Analysis Method based on Coupling Degree
BT  - Proceedings of the International Conference on Advances in Mechanical Engineering and Industrial Informatics
PB  - Atlantis Press
SP  - 582
EP  - 590
SN  - 2352-5401
UR  - https://doi.org/10.2991/ameii-15.2015.109
DO  - 10.2991/ameii-15.2015.109
ID  - Guo2015/04
ER  -