Signature generation and detection of malware families

被引:0
|
作者
Sathyanarayan, V. Sai [1 ]
Kohli, Pankaj [1 ]
Bruhadeshwar, Bezawada [1 ]
机构
[1] Int Inst Informat Technol, C STAR, Hyderabad 500032, Andhra Pradesh, India
来源
INFORMATION SECURITY AND PRIVACY | 2008年 / 5107卷
关键词
malware detection; signature generation; static analysis;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Malware detection and prevention is critical for the protection of computing systems across the Internet. The problem in detecting malware is that they evolve over a period of time and hence, traditional signature-based malware detectors fail to detect obfuscated and previously unseen malware executables. However, as malware evolves, some semantics of the original malware are preserved as these semantics are necessary for the effectiveness of the malware. Using this observation, we present a novel method for detection of malware using the correlation between the semantics of the malware and its API calls. We construct a base signature for an entire malware class rather than for a single specimen of malware. Such a signature is capable of detecting even unknown and advanced variants that belong to that class. We demonstrate our approach on some well known malware classes and show that any advanced variant of the malware class is detected from the base signature.
引用
收藏
页码:336 / 349
页数:14
相关论文
共 50 条
  • [41] MalHunter: Automatic generation of multiple behavioral signatures for polymorphic malware detection
    Razeghi Borojerdi, Haniye
    Abadi, Mahdi
    Proceedings of the 3rd International Conference on Computer and Knowledge Engineering, ICCKE 2013, 2013, : 430 - 436
  • [42] MalHunter: Automatic Generation of Multiple Behavioral Signatures for Polymorphic Malware Detection
    Borojerdi, Haniye Razeghi
    Abadi, Mahdi
    PROCEEDINGS OF THE 3RD INTERNATIONAL CONFERENCE ON COMPUTER AND KNOWLEDGE ENGINEERING (ICCKE 2013), 2013, : 430 - 436
  • [43] Discovering New Malware Families Using a Linguistic-Based Macros Detection Method
    Miura, Hiroya
    Mimura, Mamoru
    Tanaka, Hidema
    2018 SIXTH INTERNATIONAL SYMPOSIUM ON COMPUTING AND NETWORKING WORKSHOPS (CANDARW 2018), 2018, : 431 - 437
  • [44] Neural Visualization of Android Malware Families
    Gonzalez, Alejandro
    Herrero, Alvaro
    Corchado, Emilio
    INTERNATIONAL JOINT CONFERENCE SOCO'16- CISIS'16-ICEUTE'16, 2017, 527 : 574 - 583
  • [45] Representative Signature Generation for Plant Detection in Hyperspectral Images
    Ozdil, Omer
    Esin, Yunus Emre
    Demirel, Berkan
    Ozturk, Safak
    IGARSS 2018 - 2018 IEEE INTERNATIONAL GEOSCIENCE AND REMOTE SENSING SYMPOSIUM, 2018, : 2709 - 2712
  • [46] Behavior-based Worm Detection and Signature Generation
    Yao, Yu
    Lv, Junwei
    Gao, Fuxiang
    Zhang, Yanfang
    Yu, Ge
    2008 INTERNATIONAL MULTISYMPOSIUMS ON COMPUTER AND COMPUTATIONAL SCIENCES (IMSCCS), 2008, : 124 - 131
  • [47] SAGMAD-A Signature Agnostic Malware Detection System Based on Binary Visualisation and Fuzzy Sets
    Saridou, Betty
    Rose, Joseph Ryan
    Shiaeles, Stavros
    Papadopoulos, Basil
    ELECTRONICS, 2022, 11 (07)
  • [48] SK-Tree: a systematic malware detection algorithm on streaming trees via the signature kernel
    Cochrane, Thomas
    Foster, Peter
    Chhabra, Varun
    Lemercier, Maud
    Lyons, Terry
    Salvi, Cristopher
    PROCEEDINGS OF THE 2021 IEEE INTERNATIONAL CONFERENCE ON CYBER SECURITY AND RESILIENCE (IEEE CSR), 2021, : 35 - 40
  • [49] HLMD: a signature-based approach to hardware-level behavioral malware detection and classification
    Mohammad Bagher Bahador
    Mahdi Abadi
    Asghar Tajoddin
    The Journal of Supercomputing, 2019, 75 : 5551 - 5582
  • [50] HLMD: a signature-based approach to hardware-level behavioral malware detection and classification
    Bahador, Mohammad Bagher
    Abadi, Mahdi
    Tajoddin, Asghar
    JOURNAL OF SUPERCOMPUTING, 2019, 75 (08): : 5551 - 5582