网络与信息安全学报 ›› 2017, Vol. 3 ›› Issue (2): 20-30.doi: 10.11959/j.issn.2096-109x.2017.00144

• 学术论文 • 上一篇    下一篇

针对恶意代码的连续内存镜像分析方法

李伟明1(),邹德清1,孙国忠2   

  1. 1 华中科技大学计算机学院,湖北 武汉 430074
    2 曙光信息产业有限公司,北京 100080
  • 修回日期:2016-10-23 出版日期:2017-02-01 发布日期:2017-02-10
  • 作者简介:李伟明(1975-),男,湖南株洲人,博士,华中科技大学副教授,主要研究方向为信息安全。|邹德清(1973-),男,湖南湘潭人,博士,华中科技大学教授、博士生导师,主要研究方向为云计算、信息安全。|孙国忠(1973-),男,吉林大安人,博士,曙光信息产业(北京)有限公司高级工程师,主要研究方向为高性能计算、云计算。
  • 基金资助:
    国家自然科学基金资助项目(61272072);国家重点基础研究与发展计划基金资助项目(“973”计划)(2016YFB0200300)

Successive memory image analysis method for malicious codes

Wei-ming LI1(),De-qing ZOU1,Guo-zhong SUN2   

  1. 1 School of Computer Science, Huazhong University of Science and Technology, Wuhan 430074, China
    2 Dawning Information Industry Co., Ltd., Beijing 100080, China
  • Revised:2016-10-23 Online:2017-02-01 Published:2017-02-10
  • Supported by:
    The National Natural Science Foundation of China(61272072);The National Basic Research Program of China (973 Program)(2016YFB0200300)

摘要:

为了更加全面地检测恶意代码的行为,提出连续内存镜像分析技术。核心是在QEMU虚拟机中运行恶意代码样本,获取样本运行时期连续增量的内存镜像,然后按照时序解析为多个完整的内存镜像。在单个内存镜像分析的基础上,对不同时刻内存镜像做对比分析。同时设计运用可视化工具D3.js,以图表的形式直观动态地展示系统运行过程中内存状态的变化。最后实现原型系统,通过对40种恶意代码样本进行测试,检测出的恶意代码行为数量在传统单镜像内存分析的基础上增加了19.7%。

关键词: 恶意代码, 内存镜像, 对比分析, 数据可视化

Abstract:

In order to detect the behavior of malicious code more comprehensively, the technology of continuous memory image analysis was proposed. The core idea was to run malicious code in QEMU virtual machine, to obtain the memory image of the continuous increment in the running period, and then to analyze the memory image of the base and increment as the memory image. On the basis of the analysis of a single memory image, different memory images were analysised comparatively. At the same time, the visualization tool D3.js was used to visually display the change of the memory state in the process of system operation. Finally, the prototype system was tested by 40 kinds of malicious code samples, and the number of malicious code behavior was increased by 19.7% than traditional sin-gle memory image.

Key words: malware, memory image, comparative analysis, data visualization

中图分类号: 

No Suggested Reading articles found!