DiffSig: Resource Differentiation Based Malware Behavioral Concise Signature Generation - Inria - Institut national de recherche en sciences et technologies du numérique Accéder directement au contenu
Communication Dans Un Congrès Année : 2013

DiffSig: Resource Differentiation Based Malware Behavioral Concise Signature Generation

Huabiao Lu
  • Fonction : Auteur
  • PersonId : 1003073
Baokang Zhao
  • Fonction : Auteur
  • PersonId : 1003074
Xiaofeng Wang
  • Fonction : Auteur
  • PersonId : 993526
Jinshu Su
  • Fonction : Auteur
  • PersonId : 994595

Résumé

Malware obfuscation obscures malware into a different form that’s functionally identical to the original one, and makes syntactic signature ineffective. Furthermore, malware samples are huge and growing at an exponential pace. Behavioral signature is an effective way to defeat obfuscation. However, state-of-the-art behavioral signature, behavior graph, is although very effective but unfortunately too complicated and not scalable to handle exponential growing malware samples; in addition, it is too slow to be used as real-time detectors. This paper proposes an anti-obfuscation and scalable behavioral signature generation system, DiffSig, which voids information-flow tracking which is the chief culprit for the complex and inefficiency of graph behavior, thus, losing some data dependencies, but describes handle dependencies more accurate than graph behavior by restrict the profile type of resource that each handle dependency can reference to. Our experiment results show that DiffSig is scalable and efficient, and can detect new malware samples effectively.
Fichier principal
Vignette du fichier
978-3-642-36818-9_28_Chapter.pdf (172.94 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)
Loading...

Dates et versions

hal-01480181 , version 1 (01-03-2017)

Licence

Paternité

Identifiants

Citer

Huabiao Lu, Baokang Zhao, Xiaofeng Wang, Jinshu Su. DiffSig: Resource Differentiation Based Malware Behavioral Concise Signature Generation. 1st International Conference on Information and Communication Technology (ICT-EurAsia), Mar 2013, Yogyakarta, Indonesia. pp.271-284, ⟨10.1007/978-3-642-36818-9_28⟩. ⟨hal-01480181⟩
46 Consultations
167 Téléchargements

Altmetric

Partager

Gmail Facebook X LinkedIn More