• DocumentCode
    3762015
  • Title

    Automatic loop detection in the sequence of system calls

  • Author

    Mohammad Hadi Alaeiyan;Saeed Parsa

  • Author_Institution
    Department of Computer Engineering, Iran University of Science and Technology, Narmak, Tehran, 16844, Iran
  • fYear
    2015
  • Firstpage
    720
  • Lastpage
    723
  • Abstract
    Computer hardware and Internet are growing so fast nowadays, security threats of malicious executable programs are getting more serious. Malicious users to exploit as their roguish aims increased the usage of polymorphism and metamorphism malware. On the other side, hundreds of malware will appear by manual analysis daily. Manual analysis of this number of malware requires a lot of time that is uncontrollable. Automatic reverse engineering of malware based upon their behavior is our old wish that nowadays is going to be fulfilled. The main part of this aim is the detection of loops in the sequence of system calls that not only decreases the number of system calls for analysis but also constructs the schema of executed code. To this end, n-gram gets used to find similar subsequences of system call sequence to define as a loop.
  • Keywords
    "Decision support systems","Malware"
  • Publisher
    ieee
  • Conference_Titel
    Knowledge-Based Engineering and Innovation (KBEI), 2015 2nd International Conference on
  • Type

    conf

  • DOI
    10.1109/KBEI.2015.7436133
  • Filename
    7436133