arrow
Return

Framework for understanding intention-unbreakable malware

delete2023-03-27
delete0
PRE
AI
T
Tiantian Ji
B
Binxing Fang
X
Xiang Cui *
P
Peng Liao
DOI:10.1007/s11432-021-3567-ydelete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
The anti-analysis technology of malware has always been the focus in the cyberspace security field. As malware analysis techniques evolve, malware writers continually employ sophisticated anti-reverse engineering techniques to defeat and evade state-of-the-art analyzers. Therefore, to prepare for unknown attacks, studying malware analysis techniques is insufficient. More importantly, we should study new anti-analysis techniques for malware. This paper expands the concept of anti-analysis malware and defines a type of intention-unbreakable malware (IUM). To help defenders fully understand and establish a defense system against the new security threats, this paper systematically discusses IUM from the perspectives of threat discovery, threat modeling, attribute analysis, and threat assessment; in addition, this study also provides the PoC implementations of IUM and demonstrates how attackers can use this type of malware to evade advanced security analysis, that is, accurate identification of target (class) victims and intention concealment in reaching non-target (class) victims. Finally, this paper provides several mitigation directions for combating IUM.
Keywords:
malware
unbreakable property
modeling mechanism
accurate identification
intention concealment

Journal

Science China Information Sciences cover
Science China Information Sciences
IF:
7.6
Papers:
4.9K
Citations:
8.9K

Organization

B
beijing university of posts & telecommunications
Scholars:
1.4W
Papers: 1.2W
Citations: 9
G
Guangzhou University
Scholars:
1.7W
Papers: 1.3W
Citations: 1.8W