Static extracting method of software intended behavior based on API functions invoking |
| |
Authors: | Guojun Peng Xuanchen Pan Jianming Fu Huanguo Zhang |
| |
Affiliation: | School of Computer, Wuhan University, Wuhan 430072,Hubei, China |
| |
Abstract: | The method of extracting and describing the intended behavior of software precisely has become one of the key points in the fields of software behavior’s dynamic and trusted authentication. In this paper, the author proposes a specified measure of extracting SIBDS (software intended behaviors describing sets) statically from the binary executable using the software’s API functions invoking, and also introduces the definition of the structure used to store the SIBDS in detail. Experimental results demonstrate that the extracting method and the storage structure definition offers three strong properties: (i) it can describe the software’s intended behavior accurately; (ii) it demands a small storage expense; (iii) it provides strong capability to defend against mimicry attack. Foundation item: Supported by the National Natural Science Foundation of China (60673071, 60743003, 90718005, 90718006) and the National High Technology Research and Development Program of China (863 Program) (2006AA01Z442, 2007AA01Z411) |
| |
Keywords: | API functions invoking software intended behavior trusted behavior |
本文献已被 维普 SpringerLink 等数据库收录! |
|