Multi-Channel Change-Point Malware Detection

被引:5
作者
Canzanese, Raymond [1 ]
Kam, Moshe [1 ]
Mancoridis, Spiros
机构
[1] Drexel Univ, Dept Elect & Comp Engn, Philadelphia, PA 19104 USA
来源
2013 IEEE 7TH INTERNATIONAL CONFERENCE ON SOFTWARE SECURITY AND RELIABILITY (SERE) | 2013年
关键词
D O I
10.1109/SERE.2013.20
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
The complex computing systems employed by governments, corporations, and other institutions are frequently targeted by cyber-attacks designed for espionage and sabotage. The malicious software used in such attacks are typically custom-designed or obfuscated to avoid detection by traditional antivirus software. Our goal is to create a malware detection system that can quickly and accurately detect such otherwise difficult-to-detect malware. We pose the problem of malware detection as a multi-channel change-point detection problem, wherein the goal is to identify the point in time when a system changes from a known clean state to an infected state. We present a host-based malware detection system designed to run at the hypervisor level, monitoring hypervisor and guest operating system sensors and sequentially determining whether the host is infected. We present a case study wherein the detection system is used to detect various types of malware on an active web server under heavy computational load.
引用
收藏
页码:70 / 79
页数:10
相关论文
共 39 条
  • [1] [Anonymous], 2006, ULTRALARGE SCALE SYS
  • [2] [Anonymous], MICR SERV PROD
  • [3] [Anonymous], P VIR B C MCAFEE AV
  • [4] [Anonymous], COMPUTER
  • [5] [Anonymous], P 15 C USENIX SEC S
  • [6] [Anonymous], P 15 EUR I COMP ANT
  • [7] Axelsson S., 2000, ACM Transactions on Information and Systems Security, V3, P186, DOI 10.1145/357830.357849
  • [8] Basseville M, 1993, DETECTION ABRUPT CHA
  • [9] Distributed detection with multiple sensors .2. Advanced topics
    Blum, RS
    Kassam, SA
    Poor, HV
    [J]. PROCEEDINGS OF THE IEEE, 1997, 85 (01) : 64 - 79
  • [10] ASYNCHRONOUS DISTRIBUTED DETECTION
    CHANG, W
    KAM, MS
    [J]. IEEE TRANSACTIONS ON AEROSPACE AND ELECTRONIC SYSTEMS, 1994, 30 (03) : 818 - 826