Detecting Metamorphic Malware Based on Abstract Signatures

Qingxian Wang · Journal of Chinese Computer Systems · 2009

Traditional methods of detecting malware are often based on concrete signatures,such as a sequence of instructions or bytes,so it is hard for them to detect metamorphic malware. Adopting abstract signatures is a promising idea to resolve the problem. This paper focuses on the common metamorphic techniques,i.e. identical instruction substitution,garbage code insertion and instruction reordering. A type of abstract signature is defined and a method of detecting metamorphic malware is proposed. Experiments have been done towards a typical metamorphic virus Win32.Evol and comparison with other methods has also been carried out. The results show that our method is feasible.

Read the paper · More papers on PaperTik