Matches in SemOpenAlex for { <https://semopenalex.org/work/W182189571> ?p ?o ?g. }
Showing items 1 to 90 of
90
with 100 items per page.
- W182189571 abstract "Malware analysts often need to search large corpuses of obfuscated binaries for particular sequences of related instructions. The use of simple tactics, such as dead code insertion and register renaming, prevents the use of conventional, big-data search indexes. Current, state of the art malware detectors are unable to handle the size of the dataset due to their iterative approach to comparing files. Furthermore, current work is also frequently designed to act as a detector and not a search tool. I propose a system that exploits the observation that many data/control-flow relationships between instructions are preserved in the presence of obfuscations. The system will extract chains of flow-dependent instructions from a binary’s Program Dependence Graph (PDG). It will then use a representation of each chain as a key for an index that points to lists of functions (and their corresponding files). Analysts will be able to quickly search for instruction sequences by querying the index. Acknowledgments Thesis Committee: Priya Narasimhan, CMU (Advisor), Lujo Bauer, CMU, Stacy Prowell, Oak Ridge National Laboratory, Anthony Rowe, CMU. I’d like to thank my family for their support and unconditional love. I’d like to thank my advisor Priya. You’ve given me a chance to pursue my interests. Finally, I’d like to thank Cory and Chuck. You’ve shown me what it means to do malware analysis in the real world. Finally, I would like to thank Priya’s industry sponsors and Computer Emergency Response Team (CERT) for their financial support." @default.
- W182189571 created "2016-06-24" @default.
- W182189571 creator A5085584133 @default.
- W182189571 date "2014-01-01" @default.
- W182189571 modified "2023-09-27" @default.
- W182189571 title "Practical, Large-Scale Detection of Obfuscated Malware Code Via Flow Dependency Indexing" @default.
- W182189571 cites W1508225132 @default.
- W182189571 cites W1573286687 @default.
- W182189571 cites W1595564425 @default.
- W182189571 cites W1990698892 @default.
- W182189571 cites W2000931408 @default.
- W182189571 cites W2024170198 @default.
- W182189571 cites W2066220442 @default.
- W182189571 cites W2068211976 @default.
- W182189571 cites W2073944597 @default.
- W182189571 cites W2105334567 @default.
- W182189571 cites W2109518951 @default.
- W182189571 cites W2115175195 @default.
- W182189571 cites W2115392339 @default.
- W182189571 cites W2126734536 @default.
- W182189571 cites W2131523719 @default.
- W182189571 cites W2136245903 @default.
- W182189571 cites W2138644293 @default.
- W182189571 cites W2143840485 @default.
- W182189571 cites W2144344516 @default.
- W182189571 cites W2145631416 @default.
- W182189571 cites W2154529672 @default.
- W182189571 cites W2163292449 @default.
- W182189571 cites W2165721142 @default.
- W182189571 cites W3013405273 @default.
- W182189571 cites W78162143 @default.
- W182189571 cites W81538894 @default.
- W182189571 cites W2322373077 @default.
- W182189571 hasPublicationYear "2014" @default.
- W182189571 type Work @default.
- W182189571 sameAs 182189571 @default.
- W182189571 citedByCount "0" @default.
- W182189571 crossrefType "journal-article" @default.
- W182189571 hasAuthorship W182189571A5085584133 @default.
- W182189571 hasConcept C136764020 @default.
- W182189571 hasConcept C160191386 @default.
- W182189571 hasConcept C165696696 @default.
- W182189571 hasConcept C177264268 @default.
- W182189571 hasConcept C199360897 @default.
- W182189571 hasConcept C2776760102 @default.
- W182189571 hasConcept C2777382242 @default.
- W182189571 hasConcept C2779395397 @default.
- W182189571 hasConcept C38652104 @default.
- W182189571 hasConcept C41008148 @default.
- W182189571 hasConcept C541664917 @default.
- W182189571 hasConcept C75165309 @default.
- W182189571 hasConceptScore W182189571C136764020 @default.
- W182189571 hasConceptScore W182189571C160191386 @default.
- W182189571 hasConceptScore W182189571C165696696 @default.
- W182189571 hasConceptScore W182189571C177264268 @default.
- W182189571 hasConceptScore W182189571C199360897 @default.
- W182189571 hasConceptScore W182189571C2776760102 @default.
- W182189571 hasConceptScore W182189571C2777382242 @default.
- W182189571 hasConceptScore W182189571C2779395397 @default.
- W182189571 hasConceptScore W182189571C38652104 @default.
- W182189571 hasConceptScore W182189571C41008148 @default.
- W182189571 hasConceptScore W182189571C541664917 @default.
- W182189571 hasConceptScore W182189571C75165309 @default.
- W182189571 hasLocation W1821895711 @default.
- W182189571 hasOpenAccess W182189571 @default.
- W182189571 hasPrimaryLocation W1821895711 @default.
- W182189571 hasRelatedWork W1527266608 @default.
- W182189571 hasRelatedWork W1605436333 @default.
- W182189571 hasRelatedWork W1967489804 @default.
- W182189571 hasRelatedWork W1975966552 @default.
- W182189571 hasRelatedWork W2005491441 @default.
- W182189571 hasRelatedWork W2011009207 @default.
- W182189571 hasRelatedWork W2033071293 @default.
- W182189571 hasRelatedWork W2045756085 @default.
- W182189571 hasRelatedWork W2048586182 @default.
- W182189571 hasRelatedWork W2056522536 @default.
- W182189571 hasRelatedWork W2065709228 @default.
- W182189571 hasRelatedWork W2070970642 @default.
- W182189571 hasRelatedWork W2074840958 @default.
- W182189571 hasRelatedWork W2099194862 @default.
- W182189571 hasRelatedWork W2111741004 @default.
- W182189571 hasRelatedWork W2139688842 @default.
- W182189571 hasRelatedWork W2323197016 @default.
- W182189571 hasRelatedWork W2393529801 @default.
- W182189571 hasRelatedWork W2394274701 @default.
- W182189571 hasRelatedWork W1994747466 @default.
- W182189571 isParatext "false" @default.
- W182189571 isRetracted "false" @default.
- W182189571 magId "182189571" @default.
- W182189571 workType "article" @default.