Dynamic malicious code detection based on binary translator

  • Zhe Fang*
  • , Minglu Li
  • , Chuliang Weng
  • , Yuan Luo
  • *此作品的通讯作者

科研成果: 书/报告/会议事项章节会议稿件同行评审

摘要

The binary translator is a software component of a computer system. It converts binary code of one ISA into binary code of another ISA. Recent trends show that binary translators have been used to save CPU power consumption and CPU die size, which makes binary translators a possible indispensable component of future computer systems. And such situation would give new opportunities to the security of these computer systems. One of the opportunities is that we can perform malicious code checking dynamically in the layer of binary translators. This approach has many advantages, both in terms of capability of detection and checking overhead. In this paper, we proposed a working dynamic malicious code checking module integrated to an existent open-source binary translator, QEMU, and explained that our module's capability of detection is superior to other malicious code checking methods while acceptable performance is still maintained.

源语言英语
主期刊名Cloud Computing - First International Conference, CloudCom 2009, Proceedings
出版商Springer Verlag
80-89
页数10
ISBN(印刷版)3642106641, 9783642106644
DOI
出版状态已出版 - 2009
已对外发布
活动1st International Conference on Cloud Computing, CloudCom 2009 - Beijing, 中国
期限: 1 12月 20094 12月 2009

出版系列

姓名Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
5931 LNCS
ISSN(印刷版)0302-9743
ISSN(电子版)1611-3349

会议

会议1st International Conference on Cloud Computing, CloudCom 2009
国家/地区中国
Beijing
时期1/12/094/12/09

指纹

探究 'Dynamic malicious code detection based on binary translator' 的科研主题。它们共同构成独一无二的指纹。

引用此