DocumentCode :
2764083
Title :
Building malware infection trees
Author :
Morales, Jose Andre ; Main, Michael ; Luo, Weiliang ; Xu, Shouhuai ; Sandhu, Ravi
Author_Institution :
Software Eng. Inst., Carnegie Mellon Univ., Pittsburgh, PA, USA
fYear :
2011
fDate :
18-19 Oct. 2011
Firstpage :
50
Lastpage :
57
Abstract :
Dynamic analysis of malware is an ever evolving and challenging task. A malware infection tree (MiT) can assist in analysis by identifying processes and files related to a specific malware sample. In this paper we propose an abstract approach to building a comprehensive MiT based on rules describing execution events essential to malware infection strategies of files and processes. The MiT is built using strong and weak bonds between processes and files which are based on transitivity of information and creator/created relationships. The abstract approach facilitates usage on any operating system platform. We implement the rules on the Windows Vista operating system using a custom built tool named MiTCoN which was used in a small scale analysis and infection tree creation of a diverse set of 5800 known malware samples. Results analysis revealed a significant occurrent of our rules within a very short span of time. We demonstrate our rule set can effectively and efficiently build infection trees linking all related processes and files of a specific malware sample with no false positives. We also tested the possible usability of a MiT in disinfecting a system which yielded a 100% success rate.
Keywords :
invasive software; operating systems (computers); tree data structures; MiTCoN; Windows Vista operating system; abstract approach; custom built tool; dynamic malware analysis; malware infection trees; Buildings; Educational institutions; Image edge detection; Kernel; Malware;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Malicious and Unwanted Software (MALWARE), 2011 6th International Conference on
Conference_Location :
Fajardo
Print_ISBN :
978-1-4673-0031-5
Type :
conf
DOI :
10.1109/MALWARE.2011.6112326
Filename :
6112326
Link To Document :
بازگشت