ETRI-Knowledge Sharing Plaform

KOREAN
논문 검색
Type SCI
Year ~ Keyword

Detail

Conference Paper PE File Header Analysis-Based Packed PE File Detection Technique (PHAD)
Cited 41 time in scopus Share share facebook twitter linkedin kakaostory
Authors
Yang-Seo Choi, Ik-Kyun Kim, Jin-Tae Oh, Jae-Cheol Ryou
Issue Date
2008-10
Citation
International Symposium on Computer Science and its Applications (CSA) 2008, pp.28-31
Language
English
Type
Conference Paper
DOI
https://dx.doi.org/10.1109/CSA.2008.28
Abstract
In order to conceal malware, malware authors use the packing and encryption techniques. If the malware is packed or encrypted, then it is very difficult to analyze. Therefore, to prevent the harmful effects of malware and to generate signatures for malware detection, the packed and encrypted executable codes must initially be unpacked. The first step of unpacking is to detect the packed executable files. In this paper, a packed file detection technique (PHAD) based on a PE Header Analysis is proposed. In many cases, to pack and unpack the executable codes, PE files have unusual attributes in their PE headers. In this paper, these characteristics are utilized to detect the packed files. A Characteristic Vector (CV) that consists of eight elements is defined, and the Euclidean distance (ED) of the CV is calculated. The EDs of the packed files are calculated and represent the base threshold for the detection of packed files. © 2008 IEEE.
KSP Keywords
Characteristic vector, Encryption technique, Euclidean Distance, File detection, Malware detection, PE file header, detection techniques