Show simple item record

dc.contributor.advisorMing, Jiang
dc.creatorPatel, Jay Mayank
dc.date.accessioned2019-05-28T21:57:33Z
dc.date.available2019-05-28T21:57:33Z
dc.date.created2019-05
dc.date.issued2019-05-08
dc.date.submittedMay 2019
dc.identifier.urihttp://hdl.handle.net/10106/28133
dc.description.abstractMost of the malware authors use Packers, to compress an executable file and attach a stub, to the file containing the code, to decompress it at runtime, which will turn a known piece of malware into something new, that known-malware scanners can't detect. The researchers are finding ways to unpack and find the original program from such packed binaries. However, the previous study of detection for unpacking in the packed malware using different approach won’t provide many promising results. This research explores a novel approach for the detection of the unpacking process using hardware performance counters. In this approach, the unpacking process is closely monitored with Hardware Performance Counters. The HPCs shows hot spot during the unpacking process. By performing the per-process filtration, HPCs show a close relation with the decompression algorithm. For this research, the analysis is performed on a bare-metal machine. The packed executable is profiled for hardware calls using Intel® VTune™ Amplifier.
dc.format.mimetypeapplication/pdf
dc.language.isoen_US
dc.subjectHPC
dc.subjectMalware analysis
dc.subjectBinary packing
dc.subjectBinary unpacking
dc.titleON THE FEASIBILITY OF MALWARE UNPACKING WITH HARDWARE PERFORMANCE COUNTERS
dc.typeThesis
dc.degree.departmentComputer Science and Engineering
dc.degree.nameMaster of Science in Computer Science
dc.date.updated2019-05-28T21:57:48Z
thesis.degree.departmentComputer Science and Engineering
thesis.degree.grantorThe University of Texas at Arlington
thesis.degree.levelMasters
thesis.degree.nameMaster of Science in Computer Science
dc.type.materialtext


Files in this item

Thumbnail


This item appears in the following Collection(s)

Show simple item record