2009 2nd International Conference on Computer Science and Its Applications 2009
DOI: 10.1109/csa.2009.5404211
|View full text |Cite
|
Sign up to set email alerts
|

Packed PE File Detection for Malware Forensics

Abstract: In malware accident investigation, the most important thing is detection of malicious code. Signature based anti-virus software have been used in most of the accident. Malware can easily avoid signature based detection by using packing or encryption method. Because of this, packed file detection is also important. Detection methods can be divided into signature based detection and entropy based detection. Signature based detection can not detect new packing. And entropy based detection has a problem with false… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...

Citation Types

0
0
0

Year Published

2011
2011
2015
2015

Publication Types

Select...
3
1
1

Relationship

0
5

Authors

Journals

citations
Cited by 6 publications
references
References 6 publications
0
0
0
Order By: Relevance