• DocumentCode
    2897847
  • Title

    AGIS: Towards automatic generation of infection signatures

  • Author

    Li, Zhuowei ; Wang, XiaoFeng ; Liang, Zhenkai ; Reiter, Michael K.

  • Author_Institution
    Indiana Univ., Bloomington, IN
  • fYear
    2008
  • fDate
    24-27 June 2008
  • Firstpage
    237
  • Lastpage
    246
  • Abstract
    An important yet largely uncharted problem in malware defense is how to automate generation of infection signatures for detecting compromised systems, i.e., signatures that characterize the behavior of malware residing on a system. To this end, we develop AGIS, a host-based technique that detects infections by malware and automatically generates an infection signature of the malware. AGIS monitors the runtime behavior of suspicious code according to a set of security policies to detect an infection, and then identifies its characteristic behavior in terms of system or API calls. AGIS then statically analyzes the corresponding executables to extract the instructions important to the infectionpsilas mission. These instructions can be used to build a template for a static-analysis-based scanner, or a regular-expression signature for legacy scanners. AGIS also detects encrypted malware and generates a signature from its plaintext decryption loop. We implemented AGIS on Windows XP and evaluated it against real-life malware, including keyloggers, mass-mailing worms, and a well-known mutation engine. The experimental results demonstrate the effectiveness of our technique in detecting new infections and generating high-quality signatures.
  • Keywords
    application program interfaces; digital signatures; invasive software; program diagnostics; software maintenance; API call; automatic generation; host-based technique; infection signature; keylogger; legacy scanner; malware defense; mass-mailing worm; mutation engine; plaintext decryption loop; regular-expression signature; static-analysis-based scanner; Automatic control; Character generation; Computer worms; Cryptography; Detectors; Engines; Genetic mutations; Immune system; Runtime; Telecommunication traffic;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Dependable Systems and Networks With FTCS and DCC, 2008. DSN 2008. IEEE International Conference on
  • Conference_Location
    Anchorage, AK
  • Print_ISBN
    978-1-4244-2397-2
  • Electronic_ISBN
    978-1-4244-2398-9
  • Type

    conf

  • DOI
    10.1109/DSN.2008.4630092
  • Filename
    4630092