Signature generation and detection of malware families

被引:0
|
作者
Sathyanarayan, V. Sai [1 ]
Kohli, Pankaj [1 ]
Bruhadeshwar, Bezawada [1 ]
机构
[1] Int Inst Informat Technol, C STAR, Hyderabad 500032, Andhra Pradesh, India
来源
INFORMATION SECURITY AND PRIVACY | 2008年 / 5107卷
关键词
malware detection; signature generation; static analysis;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Malware detection and prevention is critical for the protection of computing systems across the Internet. The problem in detecting malware is that they evolve over a period of time and hence, traditional signature-based malware detectors fail to detect obfuscated and previously unseen malware executables. However, as malware evolves, some semantics of the original malware are preserved as these semantics are necessary for the effectiveness of the malware. Using this observation, we present a novel method for detection of malware using the correlation between the semantics of the malware and its API calls. We construct a base signature for an entire malware class rather than for a single specimen of malware. Such a signature is capable of detecting even unknown and advanced variants that belong to that class. We demonstrate our approach on some well known malware classes and show that any advanced variant of the malware class is detected from the base signature.
引用
收藏
页码:336 / 349
页数:14
相关论文
共 50 条
  • [11] DeepSign: Deep Learning for Automatic Malware Signature Generation and Classification
    David, Omid E.
    Netanyahu, Nathan S.
    2015 INTERNATIONAL JOINT CONFERENCE ON NEURAL NETWORKS (IJCNN), 2015,
  • [12] Lightweight, Effective Detection and Characterization of Mobile Malware Families
    Elish, Karim O.
    Elish, Mahmoud O.
    Almohri, Hussain M. J.
    IEEE TRANSACTIONS ON COMPUTERS, 2022, 71 (11) : 2982 - 2995
  • [13] A malware signature extraction and detection method applied to mobile networks
    Hu, Guoning
    Venugopal, Deepak
    2007 IEEE INTERNATIONAL PERFORMANCE COMPUTING AND COMMUNICATIONS CONFERENCE, VOLS 1 AND 2, 2007, : 19 - +
  • [14] Efficient Signature Generation for Classifying Cross-Architecture IoT Malware
    Alhanahnah, Mohannad
    Lin, Qicheng
    Yan, Qiben
    Zhang, Ning
    Chen, Zhenxiang
    2018 IEEE CONFERENCE ON COMMUNICATIONS AND NETWORK SECURITY (CNS), 2018,
  • [15] AutoCombo: Automatic Malware Signature Generation Through Combination Rule Mining
    Du, Min
    Hu, Wenjun
    Hewlett, William
    PROCEEDINGS OF THE 30TH ACM INTERNATIONAL CONFERENCE ON INFORMATION & KNOWLEDGE MANAGEMENT, CIKM 2021, 2021, : 3777 - 3786
  • [16] FIRMA: Malware Clustering and Network Signature Generation with Mixed Network Behaviors
    Rafique, M. Zubair
    Caballero, Juan
    RESEARCH IN ATTACKS, INTRUSIONS, AND DEFENSES, 2013, 8145 : 144 - 163
  • [17] Automatic Generation of String Signatures for Malware Detection
    Griffin, Kent
    Schneider, Scott
    Hu, Xin
    Chiueh, Tzi-cker
    RECENT ADVANCES IN INTRUSION DETECTION, PROCEEDINGS, 2009, 5758 : 101 - 120
  • [18] Automatic Benchmark Generation Framework for Malware Detection
    Liang, Guanghui
    Pang, Jianmin
    Shan, Zheng
    Yang, Runqing
    Chen, Yihang
    SECURITY AND COMMUNICATION NETWORKS, 2018,
  • [19] SigIL: A Signature-Based Approach of Malware Detection on Intermediate Language
    Fortino, Giancarlo
    Greco, Claudia
    Guzzo, Antonella
    Ianni, Michele
    COMPUTER SECURITY. ESORICS 2023 INTERNATIONAL WORKSHOPS, CPS4CIP, PT II, 2024, 14399 : 256 - 266
  • [20] A Signature-based Assistant Random Oversampling Method for Malware Detection
    Pang, Ying
    Chen, Zhenxiang
    Peng, Lizhi
    Ma, Kun
    Zhao, Chuan
    Ji, Ke
    2019 18TH IEEE INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS/13TH IEEE INTERNATIONAL CONFERENCE ON BIG DATA SCIENCE AND ENGINEERING (TRUSTCOM/BIGDATASE 2019), 2019, : 256 - 263