DocumentCode :
691699
Title :
Detecting forensically relevant information from PE executables
Author :
Jophin, Shany ; Vijayan, Mithun ; Dija, S.
Author_Institution :
Dept. Of Comput. Sci., Adi Shankara Inst. of Eng. & Technol., Kalady, India
fYear :
2013
fDate :
25-27 July 2013
Firstpage :
277
Lastpage :
282
Abstract :
Cyber forensics analysis is the procedure to find crucial evidence with respect to a crime from a digital media. Malware forensics and Network security plays a crucial role in the current scenario where malware attacks are a common problem. A malicious software which can be commonly termed as a malware would cause interruption to a computer operation and may collect necessary information or illegally access private systems. A malware may either take the form of a script, code, spyware and many other kinds of malicious programs. Reverse engineering principles are applied in this domain to analyze malware. It is the comprehensive process of breaking software to figure out how it works. This paper proposes an advanced and resource friendly malware forensics analysis procedure which uses the principles of static analysis to figure out the exact purpose of an executable file. Portable executable format can be explored with higher accuracy using the proposed method.
Keywords :
digital forensics; invasive software; program diagnostics; reverse engineering; software portability; Cyber forensics analysis; PE executables; comprehensive software breaking process; computer operation interruption; digital media; forensically relevant information detection; illegal private system access; information collection; malicious software; malware attacks; network security; portable executable format; resource friendly malware forensics analysis procedure; reverse engineering principles; static analysis principles; Accuracy; Databases; Feature extraction; Information technology; Malware; Market research; Software; Cyber Forensics; Executable File; Malware Analysis; Network Security; Portable Executable Format; Reverse Engineering;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Recent Trends in Information Technology (ICRTIT), 2013 International Conference on
Conference_Location :
Chennai
Type :
conf
DOI :
10.1109/ICRTIT.2013.6844216
Filename :
6844216
Link To Document :
بازگشت