Skip to main content
Log in

Detection of encrypted executable files based on entropy analysis to determine the randomness measure of byte sequences

  • Published:
Automatic Control and Computer Sciences Aims and scope Submit manuscript

Abstract

A method has been proposed for identifying malicious programs that use encryption as a disguise. In this paper, a modification of the statistical spectral test based on entropy analysis has been described.

This is a preview of subscription content, log in via an institution to check access.

Access this article

Price excludes VAT (USA)
Tax calculation will be finalised during checkout.

Instant access to the full article PDF.

Similar content being viewed by others

References

  1. Platonov, V.V., Programmno-apparatnye sredstva zashchity informatsii (Software and Hardware Means of Information Security), Moscow: Izd. Tsentr Akademiya, 2013.

    Google Scholar 

  2. Christian Ammann Hyperion: Implementation of a PE-Crypter, 2012.

  3. Rostovtsev, A.G. and Makhovenko, E.B., Teoreticheskaya Kriptografiya (Theoretical Cryptography), St. Petersburg: ANO NPO Professional, 2005.

    Google Scholar 

  4. Matveeva, V.S., A new way to distinguish compressed file formats from encrypted files, Probl. Inf. Bezop., Komp’yut. Sist., 2015, no. 4, pp. 131–139.

    Google Scholar 

  5. NIST SP800-22. A Statistical Test Suite for Random and Pseudorandom Number Genera tors for Cryptographic Applications, NIST, 2010, p. 131.

  6. Deitrich, C.J., Rossow, C., Freiling, F.C., Bos, H., van Steen, M., and Pohlmann, N., On Botnets that Use DNS for Command and Control, 2011.

    Book  Google Scholar 

Download references

Author information

Authors and Affiliations

Authors

Corresponding author

Correspondence to I. V. Alekseev.

Additional information

Original Russian Text © I.V. Alekseev, V.V. Platonov, 2017, published in Problemy Informatsionnoi Bezopasnosti, Komp’yuternye Sistemy.

About this article

Check for updates. Verify currency and authenticity via CrossMark

Cite this article

Alekseev, I.V., Platonov, V.V. Detection of encrypted executable files based on entropy analysis to determine the randomness measure of byte sequences. Aut. Control Comp. Sci. 51, 915–920 (2017). https://doi.org/10.3103/S0146411617080041

Download citation

  • Received:

  • Published:

  • Issue Date:

  • DOI: https://doi.org/10.3103/S0146411617080041

Keywords

Navigation