Dynamic malicious code detection based on binary translator

Zhe Fang*, Minglu Li, Chuliang Weng, Yuan Luo

*Corresponding author for this work

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

The binary translator is a software component of a computer system. It converts binary code of one ISA into binary code of another ISA. Recent trends show that binary translators have been used to save CPU power consumption and CPU die size, which makes binary translators a possible indispensable component of future computer systems. And such situation would give new opportunities to the security of these computer systems. One of the opportunities is that we can perform malicious code checking dynamically in the layer of binary translators. This approach has many advantages, both in terms of capability of detection and checking overhead. In this paper, we proposed a working dynamic malicious code checking module integrated to an existent open-source binary translator, QEMU, and explained that our module's capability of detection is superior to other malicious code checking methods while acceptable performance is still maintained.

Original languageEnglish
Title of host publicationCloud Computing - First International Conference, CloudCom 2009, Proceedings
PublisherSpringer Verlag
Pages80-89
Number of pages10
ISBN (Print)3642106641, 9783642106644
DOIs
StatePublished - 2009
Externally publishedYes
Event1st International Conference on Cloud Computing, CloudCom 2009 - Beijing, China
Duration: 1 Dec 20094 Dec 2009

Publication series

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume5931 LNCS
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

Conference1st International Conference on Cloud Computing, CloudCom 2009
Country/TerritoryChina
CityBeijing
Period1/12/094/12/09

Keywords

  • Binary translator
  • Dynamic detection
  • Malicious code

Fingerprint

Dive into the research topics of 'Dynamic malicious code detection based on binary translator'. Together they form a unique fingerprint.

Cite this