A Categorical Treatment of Malicious Behavioral Obfuscation

Romain Péchoux 1 Thanh Dinh Ta 1
1 CARTE - Theoretical adverse computations, and safety
Inria Nancy - Grand Est, LORIA - FM - Department of Formal Methods
Abstract : This paper studies malicious behavioral obfuscation through the use of a new abstract model for process and kernel interactions based on monoidal categories. In this model, program observations are consid-ered to be finite lists of system call invocations. In a first step, we show how malicious behaviors can be obfuscated by simulating the observa-tions of benign programs. In a second step, we show how to generate such malicious behaviors through a technique called path replaying and we extend the class of captured malwares by using some algorithmic transformations on morphisms graphical representation. In a last step, we show that all the obfuscated versions we obtained can be used to detect well-known malwares in practice.
Type de document :
Communication dans un congrès
T. V. Gopal; Manindra Agrawal; Angsheng Li; S. Barry Cooper. TAMC 2014, Apr 2014, Chennai, India. Springer, pp.280 - 299, 2014, Theory and Applications of Models of Computation. 〈10.1007/978-3-319-06089-7_20〉
Liste complète des métadonnées

Littérature citée [15 références]  Voir  Masquer  Télécharger

https://hal.inria.fr/hal-01084041
Contributeur : Romain Péchoux <>
Soumis le : mardi 18 novembre 2014 - 13:52:11
Dernière modification le : jeudi 11 janvier 2018 - 06:21:25
Document(s) archivé(s) le : jeudi 19 février 2015 - 11:41:46

Fichier

paper48-Ta-Pechoux.pdf
Fichiers produits par l'(les) auteur(s)

Identifiants

Collections

Citation

Romain Péchoux, Thanh Dinh Ta. A Categorical Treatment of Malicious Behavioral Obfuscation. T. V. Gopal; Manindra Agrawal; Angsheng Li; S. Barry Cooper. TAMC 2014, Apr 2014, Chennai, India. Springer, pp.280 - 299, 2014, Theory and Applications of Models of Computation. 〈10.1007/978-3-319-06089-7_20〉. 〈hal-01084041〉

Partager

Métriques

Consultations de la notice

144

Téléchargements de fichiers

218