Welcome to Journal of University of Chinese Academy of Sciences,Today is

›› 2010, Vol. 27 ›› Issue (1): 138-143.DOI: 10.7523/j.issn.2095-6134.2010.1.018

• Brief Report • Previous Articles    

A method for hidden malcode anomaly detection using dynamic control-flow analysis

PAN Jian-Feng, LIU Shou-Qun, XI Hong-Sheng, TAN Xiao-Bin   

  1. Department of Automation, University of Science and Technology of China, Hefei 230027, China
  • Received:2009-06-15 Revised:2009-07-26 Online:2010-01-15

Abstract:

The present study proposes a method for hidden malcode detection based on the analysis of dynamic control-flow. First we recorded the malcode-related control-flow paths of program, and then the control-flow paths were analyzed, by calling tree match algorithm, to detect the hidden malcode in the system. The experiments show that this method can detect hidden malcode efficiently at a high detection rate and with low false positive, and thus it can be applied to malcode detection on operating systems.

Key words: malcode, anomaly detection, dynamic control-flow, call tree edit distance

CLC Number: