• 中国计算机学会会刊
  • 中国科技核心期刊
  • 中文核心期刊
论文

Packed PE File Detection Based on Weighted Euclidean Distance Analysis

Expand
  • (Institute of Software and Intelligent Technology,Hangzhou Dianzi University,Hangzhou 310018,China)

Received date: 2009-05-21

  Revised date: 2009-08-26

  Online published: 2010-06-25

Abstract

More and more malware is appearing on the Internet, the authors of the malware want to gain illegal purposes by inserting malicious code into the users’ computers, such as achieving the users’ names and passwords. In order to prevent computers from being attcked, software analyzers need to analyze the principle of the malware, however, if the malware is packed, it is very difficult to analyze. We must unpack the malware and the first step of unpacking is to detect whether the malware is packed or not. This paper proposes a packed PE file detection method based on a weighted Euclidean distance analysis (PDWED) algorithm by analyzing and comparing the differences between the unpacked and the packed software on the PE header, which includes constructing a vector of 10 elements,distributing weighted value for each element,and calculating the weighted Euclidean distance of the vector. The experimental results show that PDWED can detect whether the software is packed or not quickly and accurately.

Cite this article

CHEN Qin,HUANG Jianjun,CHU Yiping,FANG Haiying . Packed PE File Detection Based on Weighted Euclidean Distance Analysis[J]. Computer Engineering & Science, 2010 , 32(7) : 1 -3 . DOI: 10.3969/j.issn.1007130X.2010.

Outlines

/