Loading...
- Type of Document: M.Sc. Thesis
- Language: Farsi
- Document No: 45340 (19)
- University: Sharif University of Technology
- Department: Computer Engineering
- Advisor(s): Kharrazi, Mehdi
- Abstract:
- Advances in computing and networking areas lead to advent of malwares with new and sophisticated features. One of these type of malwares are environment sensitive malwares which behave differently when finding out specific signs in the execution environment. They first was considered and defined in the context of malware analysis systems; meaning that these types of malwares stop their malicious behavior when detecting analysis machine as their execution environment. In this way they could challenge and evade analysis process. Afterwards, the domain of environment sensitive malwares went beyond the analysis systems and covered all environmental sensitivities which hinder the progress of malware's malicious activity. Therefore, it's worth identifying specific resources or features in common users' systems which cause malwares to change or to reduce their malicious behavior.
Identifying features of these types of malwares that cause them to be sensitive -- to analysis systems or common systems, is an important challenge for security researchers. Identifying these features makes analysis systems be capable of observing and analyzing malware's malicious behavior. Besides, these features can be used for creating security mechanisms on common users' systems to prevent malicious execution. In this thesis we propose a complementary approach to detect environment sensitive malwares and extract their features which cause they be sensitive to execution environment - Keywords:
- Malwares ; Static Analysis ; Environment Sensitivity ; Vaccine
- محتواي کتاب
- view