مكتبة جرير

Detecting and modeling polymorphic shellcode

كتاب مطبوع
229ر.س.
شامل ضريبة القيمة المضافة
وحدة البيع: EACH
13ر.س.شهرياً/24 شهر
المؤلف:Nbou, Omar
تاريخ النشر: 2011
تصنيف الكتاب:التقنية والكمبيوتر,الكتب الانجليزية,
عدد الصفحات:96 Pages
الصيغة:غلاف ورقي
هذا الكتاب يُطبع عند الطلب وغير قابل للاسترجاع بعد الشراء

الصيغ المتوفرة:

كتاب مطبوع

سيتم إرسال الطلب الى عنوانك

229ر.س.
شامل الضريبة

حدد خيار التوصيل الذي تفضله

أو

عن المنتج

The problem of modeling and detecting polymorphic engines shellcode is adressed in this book. By polymorphic engines, we mean programs having the ability to transform any piece of malware into many instances consisting of different code but having the same functionality as the original malware. Typically, polymorphic engines work by encrypting the target malware using various encryption techniques and providing a decryption module in order to execute the newly encrypted instance. Moreover, those engines have the ability to mutate their decryption routine making them unique from one instance to another and hard to detect. We propose a new concept of signatures, shape signatures, which cope with the highly mutated nature of those engines. The shape signatures try to identify the constant part as well as the mutated part of the deciphering routines. This combination is able to cope with the highly mutated nature of those engines in a much more efficient way compared to traditional signatures used in most intrusion detection systems. We also aim at modeling those polymorphic engines by showing that they exhibit a specific byte composition.
عرض أكثر

المواصفات

رقم الصنف9783639377736
رقم المصنع9783639377736
تاريخ النشر2011
عرض أكثر

أبلغ عن مشكلة مع هذا المنتج

مراجعات العملاء