节点文献

PE文件隐型加壳技术的研究与实现

Research and implementation of PE file stealthy shell technique

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 徐向阳解庆春刘勇俞笛刘寅

【Author】 XU Xiang-yang1,XIE Qing-chun1,2,LIU-Yong2,YU-Di1,LIU-Yin1(1.College of Computer & Communication,Hunan University,Changsha 410082,China;2.Institute of Modern Physics,Chinese Academy of Sciences,Lanzhou 730000,China)

【机构】 湖南大学计算机与通信学院中国科学院近代物理研究所

【摘要】 通过对PE(portable executable)文件格式的了解,编写PE分析工具对文件内部结构进行分析。详细介绍了对PE可执行文件加壳的全过程,在此过程中巧妙地使用MD5、CRC32等成熟的hash算法及防API断点跟踪等多种反破解技术,并采用自动隐藏加密方案,大大地提高了软件的保护力度。

【Abstract】 Wrote an analysis tool at the base of understanding the portable executable file format.It presented the whole processes of the encrypting on the PE file in detail.In these processes,used variety anti-crack techniques such as MD5,CRC32 algorithms of mature hash as well as anti-track from the interrupt of API functions,and also used some methods of automatic hiding and encrypting.The result is that the protection strength of the software is enhanced.

【关键词】 可移植的可执行文件加壳哈希算法反跟踪
【Key words】 PE fileshellhash algorithmanti-track
【基金】 国家自然科学基金委员会重点资助项目(10635090)
  • 【文献出处】 计算机应用研究 ,Application Research of Computers , 编辑部邮箱 ,2009年01期
  • 【分类号】TP31
  • 【被引频次】6
  • 【下载频次】340
节点文献中: 

本文链接的文献网络图示:

本文的引文网络