Master'sOpen Access

Dinamik sembolik uygulama ve API çağrı sıralamaları kullanarak ikili programlarda zararlı davranış tespiti

2021
0 views
0 downloads
Advisor: Doç. Dr. Aysu Betin Can

Abstract (EN)

Program analysis becomes an important part of malware detection as malware become stealthier and more complex. For example, modern malware may detect whether they are under analysis and they may use certain triggers such as time to avoid detection. However, current detection techniques turn out to be insufficient as they have limitations to detect new, obfuscated, and intelligent malware. In this thesis, we propose a behavior based malware detection methodology using API call sequence analysis. In our methodology, we combine dynamic symbolic execution and API function models to extract call sequences of a given binary program and decide whether it has a malicious sequence. In our experiments, we showed that our methodology is capable of detecting malware hiding behind evasion techniques and our methodology is applicable to a real-world problem.

Author

Dr. Fatih Tamer Tatar

How to Cite

Fatih Tamer Tatar (Master Thesis). Dinamik sembolik uygulama ve API çağrı sıralamaları kullanarak ikili programlarda zararlı davranış tespiti, 2021, Middle East Technical University.

Keywords

License

Tüm Hakları Saklıdır

This work is shared under the specified license terms.

More theses from Middle East Technical University