Polymorphic Shellcode Detection System Based on Dynamic Emulation

王兰佳,段海新,李星
DOI: https://doi.org/10.3969/j.issn.1000-3428.2008.13.003
2008-01-01
Abstract:Based on the analysis of the characteristics of polymorphic Shellcode’s behavior, an dynamic emulation based detection criterion is proposed. Using the criterion, this paper designs and implements a dynamic emulation based polymorphic Shellcode detection system, which is highly optimized in each module. With 3.3 GB real network data and 11 000 polymorphic Shellcode samples, the experiment on prototype presents zero false positive and false negative, and it improves the throughput of system.
What problem does this paper attempt to address?