Detecting Environment-Sensitive Malware Based on Taint Analysis

被引:0
|
作者
Shi, Dawei [1 ]
Tang, Xiucun [1 ]
Ye, Zhibin [1 ]
机构
[1] Jiangnan Inst Comp Technol, Wuxi, Jiangsu, Peoples R China
来源
PROCEEDINGS OF 2017 8TH IEEE INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING AND SERVICE SCIENCE (ICSESS 2017) | 2017年
关键词
malware; environment-sensitive; taint analysis; force execution; system call;
D O I
暂无
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Dynamic analysis technique extracts malicious behavior by monitoring the execution of malware. But due to the differences between analysis environment and real environment, Malware can easily hide its malicious behavior in suspicious environment. This paper proposed a method in detecting environment-sensitive malware based on taint analysis, which monitored the use of environment-sensitive features, and detected malicious behavior by executing along hidden path. Our approach firstly extracted sensitive system calls and special instructions to mark tainted features, then achieved environment-sensitive controlled jump based on taint propagation analysis while code was running, and at last forced execution along different paths according to the extraction of path jump constraint conditions. We designed and implemented a prototype that can be automatically applied on malware analysis. The evaluation of the prototype by comparing with static and dynamic tools showed it can recognize the environment-sensitive features comprehensively, and can effectively increase the ability in malware detection with high efficiency.
引用
收藏
页码:322 / 327
页数:6
相关论文
共 50 条
  • [1] Detecting Environment-Sensitive Malware
    Lindorfer, Martina
    Kolbitsch, Clemens
    Comparetti, Paolo Milani
    RECENT ADVANCES IN INTRUSION DETECTION, 2011, 6961 : 338 - 357
  • [2] FindEvasion: An Effective Environment-Sensitive Malware Detection System for the Cloud
    Jia, Xiaoqi
    Zhou, Guangzhe
    Huang, Qingjia
    Zhang, Weijuan
    Tian, Donghai
    DIGITAL FORENSICS AND CYBER CRIME, ICDF2C 2017, 2018, 216 : 3 - 17
  • [3] A malware analysis platform based on taint analysis
    Zhang, Fan
    Yang, Minghui
    Xu, Mingdi
    2013 INTERNATIONAL CONFERENCE ON COMPUTER SCIENCES AND APPLICATIONS (CSA), 2013, : 22 - 25
  • [4] Detecting Sensitive Behavior on Android with Static Taint Analysis Based on Classification
    Chen, Yayun
    Zhang, Hua
    PROCEEDINGS OF THE 4TH INTERNATIONAL CONFERENCE ON MECHATRONICS, MATERIALS, CHEMISTRY AND COMPUTER ENGINEERING 2015 (ICMMCCE 2015), 2015, 39 : 3002 - 3006
  • [5] Environment-sensitive intrusion detection
    Giffin, JT
    Dagon, D
    Jha, S
    Lee, W
    Miller, BP
    RECENT ADVANCES IN INTRUSION DETECTION, 2006, 3858 : 185 - 206
  • [6] Environment-Sensitive cloning in images
    Zhang, Yun
    Tong, Ruofeng
    VISUAL COMPUTER, 2011, 27 (6-8): : 739 - 748
  • [7] Environment-Sensitive cloning in images
    Yun Zhang
    Ruofeng Tong
    The Visual Computer, 2011, 27 : 739 - 748
  • [8] Discovery of environment-sensitive fluorescent probes for detecting and inhibiting metallo-?-lactamase
    Chen, Cheng
    Xiang, Yang
    Yang, Ke-Wu
    BIOORGANIC CHEMISTRY, 2022, 128
  • [9] ENVIRONMENT-SENSITIVE MACHINING OF NONMETALS
    WESTWOOD, AR
    AMERICAN CERAMIC SOCIETY BULLETIN, 1972, 51 (04): : 319 - &
  • [10] ENVIRONMENT-SENSITIVE FRACTURE - DESIGN CONSIDERATIONS
    TOMKINS, B
    SCOTT, PM
    METALS TECHNOLOGY, 1982, 9 (JUN): : 240 - 248