DocumentCode :
2530188
Title :
MetaAware: Identifying Metamorphic Malware
Author :
Zhang, Qinghua ; Reeves, Douglas S.
Author_Institution :
North Carolina State Univ., Raleigh
fYear :
2007
fDate :
10-14 Dec. 2007
Firstpage :
411
Lastpage :
420
Abstract :
Detection of malicious software (malware) by the use of static signatures is often criticized for being overly simplistic. Available methods of obfuscating code (so-called metamorphic malware) will invalidate the use of a fixed signature, without changing the harmful effects of the software. This paper presents a new approach for recognizing metamorphic malware. The method uses fully automated static analysis of executables to summarize and compare program semantics, based primarily on the pattern of library or system functions which are called. The proposed method has been prototyped and evaluated using randomized benchmark programs, instances of known malware program variants, and utility software available in multiple releases. The results demonstrate three important capabilities of the proposed method: (a) it does well at identifying metamorphic variants of common malware; (h) it distinguishes easily between programs that are not related; and, (c) it can identify and detect program variations, or code reuse. Such variations can be due to insertion of malware (such as viruses) into the executable of a host program. We argue that this method of metamorphic code detection will be difficult for malware writers to bypass.
Keywords :
security of data; systems analysis; malicious software; malware program variants; metamorphic malware; obfuscating code; randomized benchmark programs; static signatures; utility software; Application software; Character generation; Computer science; Computer security; Laboratories; Pattern analysis; Pattern matching; Protection; Software libraries; Viruses (medical);
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Computer Security Applications Conference, 2007. ACSAC 2007. Twenty-Third Annual
Conference_Location :
Miami Beach, FL
ISSN :
1063-9527
Print_ISBN :
978-0-7695-3060-4
Type :
conf
DOI :
10.1109/ACSAC.2007.9
Filename :
4413007
Link To Document :
بازگشت