Vis enkel innførsel

dc.contributor.authorOLSEN, KRISTOFFER RENSTRØM
dc.date.accessioned2021-10-18T10:49:39Z
dc.date.available2021-10-18T10:49:39Z
dc.date.issued2021
dc.identifier.citationOlsen, K.R. (2021) Detecting Packed PE Files : Executable file analysis for the Windows operating system Master's thesis in Cyber security (IKT523)en_US
dc.identifier.urihttps://hdl.handle.net/11250/2823655
dc.descriptionMaster's thesis in Cyber security (IKT523)en_US
dc.description.abstractMalware authors invent new methods regularly to hide and obfuscate their code. One of these methods is known as packing. An entire program is hidden inside another executable program; however, the hidden program is usually encrypted or obfuscated such that antivirus software cannot detect its real intent without unpacking it. This thesis will look into common PE packers and describe the development of an application used to detect packed PE binaries using static analysis. This thesis is useful for reverse engineers and antivirus developers; it will give some insight into the world of packing binaries, compression methods, and encryption methods. The thesis will also gather some statistics around packed PE binaries, using a prototype to analyze 225K viruses.en_US
dc.language.isoengen_US
dc.publisherUniversity of Agderen_US
dc.rightsAttribution-NonCommercial-NoDerivatives 4.0 Internasjonal*
dc.rights.urihttp://creativecommons.org/licenses/by-nc-nd/4.0/deed.no*
dc.subjectIKT523en_US
dc.titleDetecting Packed PE Files : Executable file analysis for the Windows operating systemen_US
dc.typeMaster thesisen_US
dc.rights.holder© 2021 KRISTOFFER RENSTRØM OLSENen_US
dc.subject.nsiVDP::Matematikk og Naturvitenskap: 400::Informasjons- og kommunikasjonsvitenskap: 420::Sikkerhet og sårbarhet: 424en_US
dc.source.pagenumber61en_US


Tilhørende fil(er)

Thumbnail

Denne innførselen finnes i følgende samling(er)

Vis enkel innførsel

Attribution-NonCommercial-NoDerivatives 4.0 Internasjonal
Med mindre annet er angitt, så er denne innførselen lisensiert som Attribution-NonCommercial-NoDerivatives 4.0 Internasjonal