arrow
Return

Encryption and Re-Randomization Techniques for Malware Propagation

delete2021-01-01
delete0
delete
OA
AI
A
Ahsan Rasheed Abbasi
M
Mehreen Afzal
W
Waseem Iqbal *
S
Shynar Mussiraliyeva
F
Fawad Khan
A
Awais Ur Rehman
DOI:10.1109/ACCESS.2021.3112750delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Encryption, which is essential for the protection of sensitive information can also transform any malicious content to illegible form, which can then reside in any network, undetected. Encryption of malicious payload is used by malware authors to mask their code, however, the objective of hiding the malicious code can be further improved by techniques of re-randomization. The concept of re-randomization using asymmetric cryptography has been emerged as a new area of interest for malware designers. Re-randomizing is a technique which can prevent detection of source path of a malware and makes it indistinguishable. This article extends the idea of using asymmetric cryptography for re-randomization and has proposed a novel scheme using Pailliar's asymmetric cryptosystem. Moreover, this research work illustrates the limitations of RSA for malware re-randomization. A comprehensive performance analysis of the re-randomization techniques for various malware payloads is also presented, which can be used for the detection of re-randomized malware effectively.
Keywords:
Malware
Cryptography
Encryption
Payloads
Public key cryptography
Transforms
Load modeling
Paillier cryptosystem
RSA
ElGamal
homomorphic encryption
malware encryption
re-encryption
environmental keys

Journal

IEEE Access cover
IEEE Access
IF:
3.6
Papers:
9.8W
Citations:
29.4W

Organization

N
national university of sciences & technology - pakistan
Scholars:
7.8K
Papers: 6.6K
Citations: 6
A
Al-Farabi Kazakh National University
Scholars:
3.0K
Papers: 1.5K
Citations: 1.6K