Packer Detection for Multi-Layer Executables Using Entropy Analysis

  • Bat-Erdene, Munkhbayar
  • Kim, Taebeom
  • Park, Hyundo
  • Lee, Heejo
Citations

WEB OF SCIENCE

23
Citations

SCOPUS

28

초록

Packing algorithms are broadly used to avoid anti-malware systems, and the proportion of packed malware has been growing rapidly. However, just a few studies have been conducted on detection various types of packing algorithms in a systemic way. Following this understanding, we elaborate a method to classify packing algorithms of a given executable into three categories: single-layer packing, re-packing, or multi-layer packing. We convert entropy values of the executable file loaded into memory into symbolic representations, for which we used SAX (Symbolic Aggregate Approximation). Based on experiments of 2196 programs and 19 packing algorithms, we identify that precision (97.7%), accuracy (97.5%), and recall (96.8%) of our method are respectively high to confirm that entropy analysis is applicable in identifying packing algorithms.

키워드

re-packing algorithmsoriginal entry point (OEP)multi-layer packingpiecewise aggregate approximation (PAA)symbolic aggregate approximation (SAX)entropy analysis
제목
Packer Detection for Multi-Layer Executables Using Entropy Analysis
저자
Bat-Erdene, MunkhbayarKim, TaebeomPark, HyundoLee, Heejo
DOI
10.3390/e19030125
발행일
2017-03
유형
Article
저널명
Entropy
19
3