Detecting and Modeling Polymorphic Shellcode: a New Approach - Omar Nbou - 書籍 - VDM Verlag Dr. Müller - 9783639377736 - 2011年8月26日
カバー画像とタイトルが一致しない場合、正しいのはタイトルです

Detecting and Modeling Polymorphic Shellcode: a New Approach

価格
¥ 9.099
税抜

遠隔倉庫からの取り寄せ

発送予定日 2026年1月14日 - 2026年1月27日
クリスマスプレゼントは1月31日まで返品可能です
iMusicのウィッシュリストに追加

The problem of modeling and detecting polymorphic engines shellcode is adressed in this book. By polymorphic engines, we mean programs having the ability to transform any piece of malware into many instances consisting of different code but having the same functionality as the original malware. Typically, polymorphic engines work by encrypting the target malware using various encryption techniques and providing a decryption module in order to execute the newly encrypted instance. Moreover, those engines have the ability to mutate their decryption routine making them unique from one instance to another and hard to detect. We propose a new concept of signatures, shape signatures, which cope with the highly mutated nature of those engines. The shape signatures try to identify the constant part as well as the mutated part of the deciphering routines. This combination is able to cope with the highly mutated nature of those engines in a much more efficient way compared to traditional signatures used in most intrusion detection systems. We also aim at modeling those polymorphic engines by showing that they exhibit a specific byte composition.

メディア 書籍     Paperback Book   (ソフトカバーで背表紙を接着した本)
リリース済み 2011年8月26日
ISBN13 9783639377736
出版社 VDM Verlag Dr. Müller
ページ数 96
寸法 150 × 6 × 226 mm   ·   149 g
言語 英語