arrow
返回

A framework for metamorphic malware analysis and real-time detection

delete2015-02-01
delete48
PRE
AI
S
Shahid Alam *
R
R. Nigel Horspool
I
Issa Traoré
İ
İbrahim Soğukpınar
DOI:10.1016/j.cose.2014.10.011delete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
Metamorphism is a technique that mutates the binary code using different obfuscations. It is difficult to write a new metamorphic malware and in general malware writers reuse old malware. To hide detection the malware writers change the obfuscations (syntax) more than the behavior (semantic) of such a new malware. On this assumption and motivation, this paper presents a new framework named MARD for Metamorphic Malware Analysis and Real-Time Detection. As part of the new framework, to build a behavioral signature and detect metamorphic malware in real-time, we propose two novel techniques, named ACFG (Annotated Control Flow Graph) and SWOD-CFWeight (Sliding Window of Difference and Control Flow Weight). Unlike other techniques, ACFG provides a faster matching of CFGs, without compromising detection accuracy; it can handle malware with smaller CFGs, and contains more information and hence provides more accuracy than a CFG. SWOD-CFWeight mitigates and addresses key issues in current techniques, related to the change of the frequencies of opcodes, such as the use of different compilers, compiler optimizations, operating systems and obfuscations. The size of SWOD can change, which gives. anti-malware tool developers the ability to select appropriate parameter values to further optimize malware detection. CFWeight captures the control flow semantics of a program to an extent that helps detect metamorphic malware in real-time. Experimental evaluation of the two proposed techniques, using an existing dataset, achieved detection rates in the range 94%-99.6%. Compared to ACFG, SWOD-CFWeight significantly improves the detection time, and is suitable to be used where the time for malware detection is more important as in real-time (practical) anti-malware applications. (C) 2014 Elsevier Ltd. All rights reserved.
Keyword:
End point security
Malware analysis
Malware detection
Metamorphic malware
Window of difference
Control flow analysis
Heuristics
Data mining
AI总结

AI总结

对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。

期刊

C
Computers and Security
IF:
5.4
论文数:
4.6K
被引数:
1.4W

机构

G
Gebze Technical University
学者数:
2.7K
论文数: 2.6K
被引数: 2.4K
U
University of Victoria
学者数:
1.0W
论文数: 1.0W
被引数: 1.5W
引用论文

引用论文

FTIR–ATR studies of the sorption and diffusion of acetone/water mixtures in poly(vinyl alcohol)
err2006-04-01
err0
PREAI
errLeena-Marie Döppers; Chris Sammon; Chris Breen; Jack Yarwood
err分享
err收藏
Electrical resistivity and7Li Knight shift of liquid Li-Si alloys
err1999-01-01
err0
PREAI
errJ A Meijer; C van der Marel; P Kuiper; W van der Lugt
err分享
err收藏
学者 查看更多内容