Browse > Article
http://dx.doi.org/10.3745/KIPSTC.2003.10C.7.843

An Extension of Data Flow Analysis for Detecting Polymorphic Script Virus  

Kim, Chol-Min (아주대학교 정보통신 전문대학원 정보통신공학과)
Lee, Hyoung-Jun (아주대학교 정보통신 전문대학원 정보통신공학과)
Lee, Seong-Uck (신구대학 인터넷정보과)
Hong, Man-Pyo (아주대학교 정보 및 컴퓨터공학부)
Abstract
Script viruses are easy to make a variation because they can be built easily and be spread in text format. Thus signature-based method has a limitation in detecting script viruses. In a consequence, many researches suggest simple heuristic methods, but high false-positive error is always being an obstacle. In order to overcome this problem, our previous study concentrated on analyzing data flow of codes and has low-false positive error, but still could not detect a polymorphic virus because polymorphic virus loads self body and changes it before make a descendent. We suggest a heuristic detection method which expands the detection range of previous method to include polymorphic script viruses. Expanded data flow analysis heuristic has an expanded grammar to detect Polymorphic copy Propagation. Finally, we will show the experimental result for the effectiveness of suggested method.
Keywords
Script Virus; Data Flow Analysis; Virus Polymorphism;
Citations & Related Records
연도 인용수 순위
  • Reference
1 Igor Muttik, 'STRIPPING DOWN AN AV ENGINE,' Proceeding of VIRUS BULLETIN CONFERECE, pp. 59-68, 2000
2 CERTCC-KR, '2002년 2월 바이러스 통계,' http://www.certcc.or.kr, 2002
3 Vesselin Bontchev and Katrin Tocheva, 'MACRO AND SCRIPT VIRUS POLYMORPHISM,' Proceeding of VIRUS BULLETIN CONFERENCE, pp. 406-438, 2002
4 이성욱, '정적 분석과 코드 변환을 이용한 적극적인 악성 스크립트 대응,' 아주대학교 박사학위 논문, 2002
5 Alex Shipp, 'Heuristic Detection of Viruses within Email,' 11th International Virus Bulletin Conference, 2001
6 Francisco Fernandez, 'Heuristic Engines,' VIRUS BULLETIN CONFERENCE, pp. 407-444, 2001
7 Symantec Anti-Virus Research Center, 'Understanding Heuristics,' Symantec White Paper, 1998
8 Gabor Szappanos, 'VBA Emulator Engine Design,' Proceedings of VIRUS BULLETIN CONFERENCE, pp. 373-388, 2001
9 Gabor Szappanos, 'ARE THERE ANY POLYMORPHIC MACRO VIRUSES AT ALL?,' Proceeding of VIRUS BULLETIN CONFERENCE, p. 477, 2002
10 이성욱, 배병우, 이형준, 조은선, 홍만표, '정적탐지분석 기법을 이용한 알려지지 않은 악성 스크립트 탐지,' 정보처리학회논문지C, 제9-C권 제5호, pp. 765-774, 2002
11 Alex Shipp, 'Heuristic Detection of Viruses within E-mail,' Proceedings of VIRUS BULLETIN CONFERENCE, pp. 467-471, 2001