Metamorphic Malware Detection Based on Normalization
Ran Jin, Qiang Wei, Qingxian Wang · Jisuanji gongcheng · 2008
Much of unknown malware comes from transformed known malware. This paper proposes a complete normalization scheme to resolvethe common transforming methods, including identical instructions substitution, garbage code insertion and code reordering. It implements aprototype system and a test to the system is conducted using Win32.Evol, a typical metamorphic virus. It makes a useful attempt to adoptnormalization to detect metamorphic malware.