• DocumentCode
    1923573
  • Title

    iPanda: A comprehensive malware analysis tool

  • Author

    Peidai Xie ; Xicheng Lu ; Jinshu Su ; Yongjun Wang ; Meijian Li

  • Author_Institution
    Sch. of Cornputer, Nat. Univ. of Defense Technol., Changsha, China
  • fYear
    2013
  • fDate
    28-30 Jan. 2013
  • Firstpage
    481
  • Lastpage
    486
  • Abstract
    Malware analysis is the process of dissecting a given malware sample in order to determine its purpose and functionality. It is a necessary step to develop effective detection techniques of malicious code and removal tools. The public malware analysis systems are major sources for a user to understand a malware sample. However analysis reports of those analysis systems only include what operation system resources created or accessed by the submitted malware sample, which is insufficient for a malware analyst, who expects a comprehensive analysis report. In this paper, we present iPanda, an analysts oriented comprehensive malware analysis tool. Several prevalent static and dynamic malware analysis techniques, such as detection of evading analysis techniques used by malware authors, information flow tracking, functional code fragments identifying, network behavior analysis, etc., are implemented complementarily in iPanda so that it allows a comprehensive analysis of malware to generate an analysis report including structure profile and behavior profile of the samples. The results are paramount valuable for malware analysts to perform malware detection and containment.
  • Keywords
    invasive software; comprehensive malware analysis tool; functional code fragments; iPanda; information flow tracking; malicious code; malware authors; malware sample; network behavior analysis; operation system resources; public malware analysis systems; removal tools; Cryptography; Encoding; Entropy; Feature extraction; Malware; Monitoring; Protocols; dynamic taint analysis; information flow tracking; malware analysis; network behavior;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Information Networking (ICOIN), 2013 International Conference on
  • Conference_Location
    Bangkok
  • ISSN
    1976-7684
  • Print_ISBN
    978-1-4673-5740-1
  • Electronic_ISBN
    1976-7684
  • Type

    conf

  • DOI
    10.1109/ICOIN.2013.6496427
  • Filename
    6496427