2010 Asia-Pacific Conference on Information Theory (APCIT 2010 E-BOOK)

Xi'an,China,10.1-10.2,2010

ISBN: 978-1-935068-47-1 Scientific Research Publishing, USA

E-Book 506pp Pub. Date: November 2010

Category: Computer Science & Communications

Price: $80

Title: A Trie-Based Method for Backward Analysis of Memory Instructions
Source: 2010 Asia-Pacific Conference on Information Theory (APCIT 2010 E-BOOK) (pp 348-351)
Author(s): Zhuo Han, Zhengzhou Information Science and Technology Institute, Zhengzhou 450002, China
Xiaomin Ran, Zhengzhou Information Science and Technology Institute, Zhengzhou 450002, China
Yingchun Chen, Zhengzhou Information Science and Technology Institute, Zhengzhou 450002, China
Baozhong Ge, National Digital Switching Engineering Center, Zhengzhou 450002, China
Abstract: When analyzing malware dynamically, it needs to analyze the instruction in the memory. To solve this problem, this article introduced trie structure into instruction analytical method, and analyzed backwards from a certain instruction. Our experiment demonstrate that this method has a time complex- ity of O(n), where n is the number of trie structures, So it can find useful instruction sequence rapidly. And because of the characteristic of X86 architecture, that is, the length of a instruction is not fixed, which greatly increased the number of instructions found in the process. Therefore the method can be used in malware analysis effectively.
Free SCIRP Newsletters
Copyright © 2006-2024 Scientific Research Publishing Inc. All Rights Reserved.
Top