• DocumentCode
    2976357
  • Title

    Automatic functionality detection in behavior-based IDS

  • Author

    Nykodym, Tomas ; Skormin, Victor ; Dolgikh, Andrey ; Antonakos, James

  • Author_Institution
    Binghamton Univ., Binghamton, NY, USA
  • fYear
    2011
  • fDate
    7-10 Nov. 2011
  • Firstpage
    1302
  • Lastpage
    1307
  • Abstract
    Detection of malicious functionalities presents an effective way to detect malware in behavior-based IDS. A technology including the utilization of Colored Petri Nets for the generalized description and consequent detection of specific malicious functionalities from system call data has been previously developed, verified and presented. A successful effort was made to neutralize possible attempts to obfuscate this approach. Nevertheless, the approach has two major drawbacks. First, target functionalities have to be initially specified by an expert, which is a time consuming, sometimes subjective and error prone process. Second, the identification of typical functionalities indicative of malicious programs is not generally straightforward and requires reverse engineering and careful study of many instances of malware. Our paper addresses these drawbacks, clearing the way for a full-scale practical application of this technology. We utilized graph mining and graph similarity assessment algorithms for processing system call data resulting in automatic extraction of functionalities from system call data. This enabled us to identify sets of functionalities suggesting software maliciousness and construct a general obfuscation-resilient malware detector. The paper presents the results of the implementation and testing of the described technologies on the computer network testbed.
  • Keywords
    Petri nets; invasive software; reverse engineering; automatic functionality detection; behavior-based IDS; colored Petri nets; graph mining; graph similarity assessment algorithms; malicious functionalities; malware; reverse engineering; Context; Data models; Feature extraction; Kernel; Malware; Petri nets; Behavior Based IDS; Colored Petri Nets; Signature generation;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    MILITARY COMMUNICATIONS CONFERENCE, 2011 - MILCOM 2011
  • Conference_Location
    Baltimore, MD
  • ISSN
    2155-7578
  • Print_ISBN
    978-1-4673-0079-7
  • Type

    conf

  • DOI
    10.1109/MILCOM.2011.6127482
  • Filename
    6127482