arrow
Return

Employing Program Semantics for Malware Detection

delete2015-12-01
delete81
PRE
AI
S
Smita Naval *
V
Vijay Laxmi
M
Muttukrishnan Rajarajan
M
Manoj Singh Gaur
M
Mauro Conti
DOI:10.1109/TIFS.2015.2469253delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
In recent years, malware has emerged as a critical security threat. In addition, malware authors continue to embed numerous anti-detection features to evade the existing malware detection approaches. Against this advanced class of malicious programs, dynamic behavior-based malware detection approaches outperform the traditional signature-based approaches by neutralizing the effects of obfuscation and morphing techniques. The majority of dynamic behavior detectors rely on system-calls to model the infection and propagation dynamics of malware. However, these approaches do not account an important anti-detection feature of modern malware, i.e., system-call injection attack. This attack allows the malicious binaries to inject irrelevant and independent system-calls during the program execution thus modifying the execution sequences defeating the existing system-call-based detection. To address this problem, we propose an evasion-proof solution that is not vulnerable to system-call injection attacks. Our proposed approach characterizes program semantics using asymptotic equipartition property (AEP) mainly applied in information theoretic domain. The AEP allows us to extract information-rich call sequences that are further quantified to detect the malicious binaries. Furthermore, the proposed detection model is less vulnerable to call-injection attacks as the discriminating components are not directly visible to malware authors. We run a thorough set of experiments to evaluate our solution and compare it with the existing system-call-based malware detection techniques. The results demonstrate that the proposed solution is effective in identifying real malware instances.
Keywords:
Malware
malware detection
system-calls
semantically-relevant paths
system-call injection attacks
AI Summary

AI Summary

Key information extracted from the uploaded paper, including a brief overview, abstract, background, key highlights, visual analysis, and future outlook.

Journal

IEEE Transactions on Information Forensics and Security cover
IEEE Transactions on Information Forensics and Security
IF:
8
Papers:
5.2K
Citations:
2.3W

Organization

M
malaviya national institute of technology jaipur
Scholars:
1.3K
Papers: 1.3K
Citations: 2
N
national institute of technology (nit system)
Scholars:
4.0W
Papers: 3.7W
Citations: 31
C
city st georges, university of london
Scholars:
1.2W
Papers: 1.1W
Citations: 12
researcher View more organizations