Detailed Information

Cited 0 time in webofscience Cited 0 time in scopus
Metadata Downloads

Packer Detection for Multi-Layer Executables Using Entropy Analysis

Full metadata record
DC Field Value Language
dc.contributor.authorBat-Erdene, Munkhbayar-
dc.contributor.authorKim, Taebeom-
dc.contributor.authorPark, Hyundo-
dc.contributor.authorLee, Heejo-
dc.date.accessioned2021-09-03T08:54:21Z-
dc.date.available2021-09-03T08:54:21Z-
dc.date.created2021-06-16-
dc.date.issued2017-03-
dc.identifier.issn1099-4300-
dc.identifier.urihttps://scholar.korea.ac.kr/handle/2021.sw.korea/84257-
dc.description.abstractPacking algorithms are broadly used to avoid anti-malware systems, and the proportion of packed malware has been growing rapidly. However, just a few studies have been conducted on detection various types of packing algorithms in a systemic way. Following this understanding, we elaborate a method to classify packing algorithms of a given executable into three categories: single-layer packing, re-packing, or multi-layer packing. We convert entropy values of the executable file loaded into memory into symbolic representations, for which we used SAX (Symbolic Aggregate Approximation). Based on experiments of 2196 programs and 19 packing algorithms, we identify that precision (97.7%), accuracy (97.5%), and recall (96.8%) of our method are respectively high to confirm that entropy analysis is applicable in identifying packing algorithms.-
dc.languageEnglish-
dc.language.isoen-
dc.publisherMDPI-
dc.titlePacker Detection for Multi-Layer Executables Using Entropy Analysis-
dc.typeArticle-
dc.contributor.affiliatedAuthorLee, Heejo-
dc.identifier.doi10.3390/e19030125-
dc.identifier.scopusid2-s2.0-85024404913-
dc.identifier.wosid000400578900039-
dc.identifier.bibliographicCitationENTROPY, v.19, no.3-
dc.relation.isPartOfENTROPY-
dc.citation.titleENTROPY-
dc.citation.volume19-
dc.citation.number3-
dc.type.rimsART-
dc.type.docTypeArticle-
dc.description.journalClass1-
dc.description.journalRegisteredClassscie-
dc.description.journalRegisteredClassscopus-
dc.relation.journalResearchAreaPhysics-
dc.relation.journalWebOfScienceCategoryPhysics, Multidisciplinary-
dc.subject.keywordAuthorre-packing algorithms-
dc.subject.keywordAuthororiginal entry point (OEP)-
dc.subject.keywordAuthormulti-layer packing-
dc.subject.keywordAuthorpiecewise aggregate approximation (PAA)-
dc.subject.keywordAuthorsymbolic aggregate approximation (SAX)-
dc.subject.keywordAuthorentropy analysis-
Files in This Item
There are no files associated with this item.
Appears in
Collections
Graduate School > Department of Computer Science and Engineering > 1. Journal Articles

qrcode

Items in ScholarWorks are protected by copyright, with all rights reserved, unless otherwise indicated.

Related Researcher

Researcher Lee, Hee jo photo

Lee, Hee jo
컴퓨터학과
Read more

Altmetrics

Total Views & Downloads

BROWSE