摘要
逆向分析是恶意程序取证的常用方法之一,在揭示恶意程序意图及行为方面发挥着其他方法无法比拟的作用。在对逆向分析基本概念、方法、工具进行介绍的基础上,结合中国大陆地区一起利用恶意程序窃取QQ账号与密码的真实案例,从查壳、脱壳、断点设置、程序跟踪、关键信息获取等方面详细描述了针对恶意程序进行逆向分析的全过程。
The reverse analysis process is an advanced and efficient method that exposes the intention and process of malwares.This paper introduces the basic concepts,methods,and tools of the reverse analysis process.A case study of a malware in China,which was used to obtain QQ accounts and passwords,is presented to illustrate the whole process of the reverse analysis process of malware from the aspects of checking pack,unpacking,breakpoint setting,program tracing,key information acquiring and other facets.
出处
《中国司法鉴定》
北大核心
2011年第6期54-58,共5页
Chinese Journal of Forensic Sciences