arrow
返回

Employing Program Semantics for Malware Detection

delete2015-12-01
delete81
PRE
AI
S
Smita Naval *
V
Vijay Laxmi
M
Muttukrishnan Rajarajan
M
Manoj Singh Gaur
M
Mauro Conti
DOI:10.1109/TIFS.2015.2469253delete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
In recent years, malware has emerged as a critical security threat. In addition, malware authors continue to embed numerous anti-detection features to evade the existing malware detection approaches. Against this advanced class of malicious programs, dynamic behavior-based malware detection approaches outperform the traditional signature-based approaches by neutralizing the effects of obfuscation and morphing techniques. The majority of dynamic behavior detectors rely on system-calls to model the infection and propagation dynamics of malware. However, these approaches do not account an important anti-detection feature of modern malware, i.e., system-call injection attack. This attack allows the malicious binaries to inject irrelevant and independent system-calls during the program execution thus modifying the execution sequences defeating the existing system-call-based detection. To address this problem, we propose an evasion-proof solution that is not vulnerable to system-call injection attacks. Our proposed approach characterizes program semantics using asymptotic equipartition property (AEP) mainly applied in information theoretic domain. The AEP allows us to extract information-rich call sequences that are further quantified to detect the malicious binaries. Furthermore, the proposed detection model is less vulnerable to call-injection attacks as the discriminating components are not directly visible to malware authors. We run a thorough set of experiments to evaluate our solution and compare it with the existing system-call-based malware detection techniques. The results demonstrate that the proposed solution is effective in identifying real malware instances.
Keyword:
Malware
malware detection
system-calls
semantically-relevant paths
system-call injection attacks
AI总结

AI总结

对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。

期刊

IEEE Transactions on Information Forensics and Security 封面图
IEEE Transactions on Information Forensics and Security
IF:
8
论文数:
5.2K
被引数:
2.3W

机构

M
malaviya national institute of technology jaipur
学者数:
1.3K
论文数: 1.3K
被引数: 2
N
national institute of technology (nit system)
学者数:
4.0W
论文数: 3.7W
被引数: 31
C
city st georges, university of london
学者数:
1.2W
论文数: 1.1W
被引数: 12
学者 查看更多机构
引用论文

引用论文

Effects of floral preservative solutions for vase life evaluation of Gerbera
err2016-01-01
err0
PREAI
errH. Mehraj; I. H. Shiam; T, Taufique; M. Shamsuzzoha; A. F. M. Jamal Uddin
err分享
err收藏
High purity copper nanoparticles via sonoelectrochemical approach
err2019-10-10
err0
PREAI
errMuhammad Murtaza; Naveed Hussain; Huang Ya; Hui Wu
err分享
err收藏
err
IF0
err
err0
PREAI
err
err分享
err收藏
A search for atomic hydrogen in clusters of galaxies
err1978-04-01
err0
PREAI
errM. P. Haynes; R. L. Brown; M. S. Roberts
err分享
err收藏
学者 查看更多内容