ENDMal: An anti-obfuscation and collaborative malware detection system using syscall sequences

被引:11
作者
Lu, Huabiao [1 ]
Wang, Xiaofeng [1 ]
Zhao, Baokang [1 ]
Wang, Fei [1 ]
Su, Jinshu [1 ]
机构
[1] Natl Univ Def Technol, Sch Comp, Changsha, Hunan, Peoples R China
基金
高等学校博士学科点专项科研基金;
关键词
Behavior-based malware detection; Anti-obfuscation; Program behavior presentation; End-network collaboration; Syscall sequences;
D O I
10.1016/j.mcm.2013.03.008
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
Malware obfuscation obscures malware into different versions, making traditional syntactic nature based detection ineffective. Furthermore, with the huge and exponentially growing number of malware samples, existing malware detection systems are either evaded by malware obfuscation, or overwhelmed by numerous malware samples. This paper proposes an anti-obfuscation, scalable and collaborative malware detection system-ENDMal. ENDMal identifies the program that behaves suspiciously in end-hosts and similarly between a group of suspicious programs in a wide area as malicious. We present the Iterative Sequence Alignment (ISA) method to defeat malware obfuscation. Instead of using complex behavior graph, we propose the Handle dependences and Probabilistic Ordering Dependence (HPOD) technology to represent the program behaviors. In addition, we design a novel information sharing infrastructure, RENShare, to collaboratively congregate the group characteristics of programs spreading over different network areas. Our experimental results show that ENDMal can detect unknown malwares much faster than the centralized detection system and is more effective than the existing distributed detection system. (C) 2013 Elsevier Ltd. All rights reserved.
引用
收藏
页码:1140 / 1154
页数:15
相关论文
共 34 条
[1]  
Albus J.S., 2001, Engineering of mind: An introduction to the science of intelligent systems
[2]  
[Anonymous], P 6 JOINT M EUR SOFT
[3]  
[Anonymous], P 1996 IEEE S SEC PR
[4]  
[Anonymous], 2006, ACM COMPUTING SURVEY
[5]  
Babic D., 2011, P 23 INT C COMP AID
[6]  
Caballero J., 2011, USENIX SEC 11
[7]   WormShield: Fast worm signature generation with distributed fingerprint aggregation [J].
Cai, Min ;
Hwang, Kai ;
Pan, Jianping ;
Papadopoulos, Christos .
IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2007, 4 (02) :88-104
[8]  
Chien Eric., DOWNADUP ATTEMPTS SM
[9]  
CHRISTODORESCU M, 2004, ACM SIGSOFT INT S SO
[10]  
Clemens K., 2009, USENIX SEC 09