The Problem of Malware Packing and its Occurrence in Harmless Software
Jana Šťastná, Martin Tomášek · Acta Electrotechnica et Informatica · 2016
Analysis of software behaviour and its other properties is largely used as a method for uncovering malicious features in software, especially in cases of unknown malware.Traditional malware signatures can be circumvented, e.g. by obfuscation, therefore in our endeavour to formulate malware behavioural signatures we study behaviour and various properties detectable in malware.However, in this article we present different point of view on this issue.In our experiments we analyse a set of freely available software that is harmless and compare data extracted from analysis with malicious programs.In this article we focus on results related to so-called packing and show that this typical malware feature may be present in harmless software as well.