Slide 5
Slide 5 text
5
…
sys_ioctl()
sys_open()
sys_read()
sys_setpgid()
sys_setsid()
sys_fork()
…
Time
n-gram
[Forrest 1996]
FSA [Sekar 2001,
Wagner 2001]
Xj+1
Xj
…
Xi+1
Xi
…
X1
X0
Yj+1
Yj
…
Yi+1
Yi
…
Y1
Y0
PDA [Feng 2003, Feng
2004, Giffin 2004]
x = 1
y = x+1
y = x*2
w = x*y
Data analysis [Giffin 2006,
Bhatkar 2006]
Machine learning [Lee 1998,
Mutz 2006, Xu 2015]
Static Program Analysis
Dynamic Program Analysis
Hybrid detection
[Gao 2004, Liu 2005]
+
[Wagner 2002]
[Sharif 2007]
[Forrest 2008]
[Feng 2004]
[Chandola 2009]