arrow
返回

Proactive Detection of Computer Worms Using Model Checking

delete2010-10-01
delete27
delete
OA
AI
J
Johannes Kinder *
S
Stefan Katzenbeisser
C
Christian Schallhart
H
Helmut Veith
DOI:10.1109/TDSC.2008.74delete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
Although recent estimates are speaking of 200,000 different viruses, worms, and Trojan horses, the majority of them are variants of previously existing malware. As these variants mostly differ in their binary representation rather than their functionality, they can be recognized by analyzing the program behavior, even though they are not covered by the signature databases of current antivirus tools. Proactive malware detectors mitigate this risk by detection procedures that use a single signature to detect whole classes of functionally related malware without signature updates. It is evident that the quality of proactive detection procedures depends on their ability to analyze the semantics of the binary. In this paper, we propose the use of model checking-a well-established software verification technique-for proactive malware detection. We describe a tool that extracts an annotated control flow graph from the binary and automatically verifies it against a formal malware specification. To this end, we introduce the new specification language CTPL, which balances the high expressive power needed for malware signatures with efficient model checking algorithms. Our experiments demonstrate that our technique indeed is able to recognize variants of existing malware with a low risk of false positives.
Keyword:
Invasive software
model checking

期刊

IEEE Transactions on Dependable and Secure Computing 封面图
IEEE Transactions on Dependable and Secure Computing
IF:
7.5
论文数:
2.5K
被引数:
9.6K

机构

T
Technische Universitat Wien
学者数:
1.3W
论文数: 1.1W
被引数: 21
U
university of oxford
学者数:
9.8W
论文数: 8.6W
被引数: 137
T
Technical University of Darmstadt
学者数:
1.3W
论文数: 10.0K
被引数: 1.2W
学者 查看更多机构
引用论文

引用论文

err分享
err收藏
High Efficiency Ring-Resonator Filter With NiSi Heater
err2012-03-01
err0
PREAI
errQing Fang; Junfeng Song; Xianshu Luo; Lianxi Jia; Mingbin Yu; Guoqiang Lo; Yuliang Liu
err分享
err收藏
学者 查看更多内容