Research on Malicious Code Detection Technology Based on Monitoring Win32 API Calls

Zhi Xue · Information Security and Communications Privacy · 2009

This paper analyzes first the existing dynamic malicious code detection technology and its deficiencies, and points out the probability that those technologies may be affected by mimetic attack and bypass attack of the malicious code. Then, it proposes an API trap technology and call address confusion technology for preventing the bypass attack and mimetic attack, thus achieving a malicious code detection system based on Win32 API calls monitoring technology. The experiment indicates that the system could detect the known and unknown malicious code.

Read the paper · More papers on PaperTik