Title :
Parallel analysis of polymorphic viral code using automated deduction system
Author_Institution :
Nat. Inst. of Inf. & Commun. Technol., Koganei
fDate :
July 30 2007-Aug. 1 2007
Abstract :
As malicious code has become more sophisticated and pervasive, faster and more effective system for forensics and prevention is important. Particularly, quick analysis of polymorphic (partly encrypted) viral code is necessary. In this paper we propose a parallel analysis of polymorphic viral code using automated deduction system. In proposed system, decipher routine and its parameters are detected by parallelized automated theorem proving. We apply the weighting and look-ahead heuristics for parallel analysis. We run several detection programs with different computing strategies for analyzing target viral binary code. When the fastest detection process is finished with computing time T(0), remaining detection processes with T(1..n) can be terminated in T(0). In experiment, computing time for detection is reduced with average rate about 46%. In about a half of all cases, T(0) * 3 les T(max) where T(max) is computing time without our strategy. That is, our parallel system makes detection program faster without appending hardware computing resources. Our system is lightweight and effective for reverse engineering and computer forensics.
Keywords :
computer viruses; cryptography; parallel algorithms; reverse engineering; theorem proving; automated deduction system; computer forensics; decipher routine; detection process; look ahead heuristics; malicious code; parallel analysis; parallelized automated theorem proving; polymorphic viral code; reverse engineering; software encryption; target viral binary code; Application software; Artificial intelligence; Assembly; Binary codes; Communications technology; Cryptography; Distributed computing; Forensics; Information analysis; Software engineering;
Conference_Titel :
Software Engineering, Artificial Intelligence, Networking, and Parallel/Distributed Computing, 2007. SNPD 2007. Eighth ACIS International Conference on
Conference_Location :
Qingdao
Print_ISBN :
978-0-7695-2909-7
DOI :
10.1109/SNPD.2007.417