• DocumentCode
    3349076
  • Title

    Classification and detection of metamorphic malware using value set analysis

  • Author

    Leder, Felix ; Steinbock, Bastian ; Martini, Peter

  • Author_Institution
    Inst. of Comput. Sci. IV, Univ. of Bonn, Bonn, Germany
  • fYear
    2009
  • fDate
    13-14 Oct. 2009
  • Firstpage
    39
  • Lastpage
    46
  • Abstract
    Metamorphic malware changes the structure of its code from infection to infection. This makes it very hard to classify or to detect. While the byte-sequence of two variants may be completely different, the core functionality of the malware has to stay the same. This includes the use of flags and constants that have to be consistent at specific points. We present a novel approach that allows us to detect metamorphic variants. Based on this detection, it is also possible to classify new samples to a metamorphic family. Our approach identifies variants by tracking the use of consistent values throughout the malware. Our evaluation shows a 100% detection rate with 0 false positives for all metamorphic samples that do not change their behavior.
  • Keywords
    invasive software; pattern classification; byte sequence; metamorphic malware classification; metamorphic variant detection; value set analysis; Computer science; Counting circuits; Cryptography; Libraries; Protocols; Sockets; Statistics;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Malicious and Unwanted Software (MALWARE), 2009 4th International Conference on
  • Conference_Location
    Montreal, QC
  • Print_ISBN
    978-1-4244-5786-1
  • Type

    conf

  • DOI
    10.1109/MALWARE.2009.5403019
  • Filename
    5403019