DocumentCode :
3062666
Title :
Malware Profiler Based on Innovative Behavior-Awareness Technique
Author :
Dai, Shih-Yao ; Fyodor, Yarochkin ; Kuo, Sy-Yen ; Wu, Ming-Wei ; Huang, Yennun
Author_Institution :
Adv. Res. Center, Inst. for Inf. Ind., Taipei, Taiwan
fYear :
2011
fDate :
12-14 Dec. 2011
Firstpage :
314
Lastpage :
319
Abstract :
In order to steal valuable data, hackers are uninterrupted research and development new techniques to intrude computer systems. Opposite to hackers, security researchers are uninterrupted analysis and tracking new malicious techniques for protecting sensitive data . There are a lot of existing analyzers can be used to help security researchers to analyze and track new malicious techniques. However, these existing analyzers cannot provide sufficient information to security researchers to perform precise assessment and deep analysis. In this paper, we introduce a behavior-based malicious software profiler, named Holography platform, to assist security researchers to obtain sufficient information. Holography platform analyzes virtualization hardware data, including CPU instructions, CPU registers, memory data and disk data, to obtain high level behavior semantic of all running processes. High level behavior semantic can provide sufficient information to security researchers to perform precise assessment and deep analysis new malicious techniques, such as malicious advertisement attack(malvertising attack).
Keywords :
advertising data processing; data analysis; invasive software; program diagnostics; virtualisation; CPU instructions; CPU registers; behavior-based malicious software profiler; computer system intrusion; disk data; holography platform; innovative behavior-awareness technique; malicious advertisement attack; malicious techniques; malvertising attack; memory data; sensitive data protection; uninterrupted analysis; uninterrupted tracking; valuable data stealing; virtualization hardware data analysis; Browsers; HTML; Holography; Malware; Topology; Web pages; complete resource topology; dynamic analysis; malvertising; malware; virtual machine;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Dependable Computing (PRDC), 2011 IEEE 17th Pacific Rim International Symposium on
Conference_Location :
Pasadena, CA
Print_ISBN :
978-1-4577-2005-5
Electronic_ISBN :
978-0-7695-4590-5
Type :
conf
DOI :
10.1109/PRDC.2011.53
Filename :
6133104
Link To Document :
بازگشت