Proceedings of the 2015 Symposium and Bootcamp on the Science of Security 2015
DOI: 10.1145/2746194.2746213
|View full text |Cite
|
Sign up to set email alerts
|

Packer classifier based on PE header information

Abstract: Run-time binary packers are used in malware manufacturing to obfuscate the contents of the executable files. Such packing has proved an obstacle for antivirus software that relies on signatures, as the binary contents of packed malware often bears no resemblance to the original code on which the signature was generated. A naive approach, then, is to first attempt to unpack the malware before applying a signature. Unfortunately, malware authors make use of automated tools that drastically reduce the cost of con… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
1
1
1

Citation Types

0
4
0

Year Published

2018
2018
2024
2024

Publication Types

Select...
4

Relationship

0
4

Authors

Journals

citations
Cited by 4 publications
(4 citation statements)
references
References 1 publication
0
4
0
Order By: Relevance
“…Jin et al [21] proposed a PE header-based method for packer classification, achieving around 0.99% precision and recall. Similar to [22], the approach used PE file header analysis with nine features and the Euclidean distance for classification.…”
Section: Static Analysismentioning
confidence: 99%
“…Jin et al [21] proposed a PE header-based method for packer classification, achieving around 0.99% precision and recall. Similar to [22], the approach used PE file header analysis with nine features and the Euclidean distance for classification.…”
Section: Static Analysismentioning
confidence: 99%
“…Jin et al proposed a method to classify packers based on portable executable (PE) header information. Laxmi et al proposed a packer analysis method called PEAL (Packer Executable AnaLysis), which uses extracted features from the PE header, such as the number of sections, section name, size of code, image base, etc.…”
Section: Related Workmentioning
confidence: 99%
“…The PE header contains the starting addresses of sections, and the starting addresses and section names of encrypted sections for well‐known packers are known to the public, as shown in Table . Some of the previous packer detection methods use information obtained from only the header, but this information can be easily modified by attackers to avoid detection.…”
Section: Our Proposed Packer Identifiermentioning
confidence: 99%
See 1 more Smart Citation