Dinamik sembolik uygulama ve API çağrı sıralamaları kullanarak ikili programlarda zararlı davranış tespiti
2021
0 views
0 downloads
Advisor: Doç. Dr. Aysu Betin Can
Abstract (EN)
Program analysis becomes an important part of malware detection as malware become stealthier and more complex. For example, modern malware may detect whether they are under analysis and they may use certain triggers such as time to avoid detection. However, current detection techniques turn out to be insufficient as they have limitations to detect new, obfuscated, and intelligent malware. In this thesis, we propose a behavior based malware detection methodology using API call sequence analysis. In our methodology, we combine dynamic symbolic execution and API function models to extract call sequences of a given binary program and decide whether it has a malicious sequence. In our experiments, we showed that our methodology is capable of detecting malware hiding behind evasion techniques and our methodology is applicable to a real-world problem.
Author
Fatih Tamer Tatar
How to Cite
Fatih Tamer Tatar (Master Thesis). Dinamik sembolik uygulama ve API çağrı sıralamaları kullanarak ikili programlarda zararlı davranış tespiti, 2021, Middle East Technical University.
Keywords
License
Tüm Hakları Saklıdır
This work is shared under the specified license terms.
More theses from Middle East Technical University
- Augustus'un Roma'daki anıt mezarının bir okuması(2020)
- Anarşizm ve adalet(2021)
- Romanlar üzerinden İslami toplumu kurgulamak-İslami edebiyatta kolektif kimliğin oluşturulması ve katılım problemi(2020)
- Türk savunma sanayii için bir Ar-Ge yol haritası(2020)
- Sürdürülebilir kalkınma gündeminin hayata geçirilmesinde ulusal insan hakları kurumlarının rolünü anlamak: Avrupa örneği(2020)
- Geç Roma ve Bizans Anadolusu'nda rotalar ve iletişim (M.S. 4.-9. yüzyıllar)(2020)
