Automatically Inferring Malware Signatures for Anti-Virus Assisted Attacks

被引:23
|
作者
Wressnegger, Christian [1 ]
Freeman, Kevin [2 ]
Yamaguchi, Fabian [1 ]
Rieck, Konrad [1 ]
机构
[1] TU Braunschweig, Inst Syst Secur, Braunschweig, Germany
[2] Univ Gottingen, Inst Comp Sci, Gottingen, Germany
来源
PROCEEDINGS OF THE 2017 ACM ASIA CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY (ASIA CCS'17) | 2017年
关键词
Anti-Virus; Malware; Signatures; Attacks;
D O I
10.1145/3052973.3053002
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Although anti-virus software has significantly evolved over the last decade, classic signature matching based on byte patterns is still a prevalent concept for identifying security threats. Anti-virus signatures are a simple and fast detection mechanism that can complement more sophisticated analysis strategies. However, if signatures are not designed with care, they can turn from a defensive mechanism into an instrument of attack. In this paper, we present a novel method for automatically deriving signatures from anti-virus software and discuss how the extracted signatures can be used to attack sensible data with the aid of the virus scanner itself. To this end, we study the practicability of our approach using four commercial products and exemplary demonstrate anti-virus assisted attacks in three different scenarios.
引用
收藏
页码:587 / 598
页数:12
相关论文
共 39 条
  • [31] The Anti-virus Properties of Nano-Chinese Medicine Microcapsule Treated Fabrics
    Wang Jin-mei
    Xu Xiao-wei
    Zhou Ying
    TEXTILE BIOENGINEERING AND INFORMATICS SYMPOSIUM PROCEEDINGS, VOLS 1 AND 2, 2008, : 61 - 67
  • [32] Microstructure and Photocatalytic Activity of the Anti-Virus CaWO4:Eu3+ Nanoparticles
    Liang, Dong
    Cao, Lin
    Jia, Chengchang
    Cong, Wang
    Xiong, Sang
    Shu, Xiaoning
    Chang, Yuhong
    Cui, Zhaowen
    NANOSCIENCE AND NANOTECHNOLOGY LETTERS, 2015, 7 (04) : 353 - 357
  • [33] Catch Me If You Can: Evaluating Android Anti-Malware Against Transformation Attacks
    Rastogi, Vaibhav
    Chen, Yan
    Jiang, Xuxian
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2014, 9 (01) : 99 - 108
  • [35] A Novel Software-based MD5 Checksum Lookup Scheme for Anti-virus Systems
    Huang, Nen-Fu
    Kao, Chia-Nan
    Liu, Rong-Tai
    2011 7TH INTERNATIONAL WIRELESS COMMUNICATIONS AND MOBILE COMPUTING CONFERENCE (IWCMC), 2011, : 207 - 212
  • [36] Tri-tier immune system in anti-virus and software fault diagnosis of mobile immune robot based on normal model
    Gong, Tao
    Cai, Zixing
    JOURNAL OF INTELLIGENT & ROBOTIC SYSTEMS, 2008, 51 (02) : 187 - 201
  • [37] Tri-tier Immune System in Anti-virus and Software Fault Diagnosis of Mobile Immune Robot Based on Normal Model
    Tao Gong
    Zixing Cai
    Journal of Intelligent and Robotic Systems, 2008, 51 : 187 - 201
  • [38] A novel mechanical plant compression system for biomass fuel and acquisition of squeezed liquid with water-soluble lignin as anti-virus materials
    Ohara, Toshiaki
    Yuasa, Ken
    Kimura, Kentaro
    Komaki, Shiho
    Nishina, Yuta
    Matsukawa, Akihiro
    JOURNAL OF MATERIAL CYCLES AND WASTE MANAGEMENT, 2023, 25 (01) : 249 - 257
  • [39] A novel mechanical plant compression system for biomass fuel and acquisition of squeezed liquid with water-soluble lignin as anti-virus materials
    Toshiaki Ohara
    Ken Yuasa
    Kentaro Kimura
    Shiho Komaki
    Yuta Nishina
    Akihiro Matsukawa
    Journal of Material Cycles and Waste Management, 2023, 25 : 249 - 257