Function classification for the retro-engineering of malwares - INRIA - Institut National de Recherche en Informatique et en Automatique Accéder directement au contenu
Communication Dans Un Congrès Année : 2016

Function classification for the retro-engineering of malwares

Guillaume Bonfante
  • Fonction : Auteur
  • PersonId : 864819
Julien Oury--Nogues
  • Fonction : Auteur

Résumé

In the past ten years, our team has developed a method called morphological analysis that deals with malware detection. Morphological analysis focuses on algorithms. Here, we want to identify programs through their functions, and more precisely with the intention of those functions. The intention is described as a vector in a high dimensional vector space in the spirit of compositional semantics. We show how to use the intention of functions for their clustering. In a last step, we describe some experiments showing the relevance of the clustering and some of some possible applications for malware identification.
Fichier principal
Vignette du fichier
paper.pdf (501.14 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)

Dates et versions

hal-03178819 , version 1 (24-03-2021)

Identifiants

  • HAL Id : hal-03178819 , version 1

Citer

Guillaume Bonfante, Julien Oury--Nogues. Function classification for the retro-engineering of malwares. 9th International Symposium Foundations and Practice of Security, Oct 2016, Quebec, Canada. ⟨hal-03178819⟩
58 Consultations
205 Téléchargements

Partager

Gmail Facebook X LinkedIn More