DocumentCode :
1753599
Title :
Metaware — An extensible malware detection and removal toolkit
Author :
Yee, Chan Lee ; Chuan, Lee Ling ; Ismail, Mahamod ; Jumari, Kasmiran
Author_Institution :
Dept. of Electr., Electron. & Syst. Eng., Univ. Kebangsaan Malaysia, Bangi, Malaysia
fYear :
2011
fDate :
13-16 Feb. 2011
Firstpage :
996
Lastpage :
1000
Abstract :
Malicious code is a threat to computer security globally. The threat is evolving and leaving challenges for security specialists to improve the detection accuracy. Hence, it is imperative to optimize the traditional manual analysis method by automatic malicious code analysis system. Automatic protocol reverse-engineering is important for many security applications, including the verification of objects and detections of malware. In this paper, we propose a new approach to computer security via automating malware analysis. This project uses combination of auto-unpacked, heuristic, disassembler and emulator techniques to find and block malicious program before the malicious software executed locally. Auto-unpacked contains self-decryption algorithms, where the script codes help quickly decipher script bodies for further analysis. Heuristic analysis is designed to analyze disassemble code contain within a suspicious program. The disassemble code of the suspicious file is compared with a known virus signature database. If the disassemble code matches with the code of the database signature, the file is flagged. The emulator is design to scans code, imitates the way they are executing, and monitoring their actions, preventing any actual damage from being dealt to the computer system or user data. Verdicts on whether or not a program poses a threat are issued based on the results of behaviour analyses. The emulator makes it possible to find malicious code that are intentionally masked to prevent detection using encryption and obfuscated code. Overall, we present our motivation for designing the system and give an overview of the system architecture.
Keywords :
invasive software; learning (artificial intelligence); auto-unpacked technique; automatic malicious code analysis system; computer security; disassembler technique; emulator technique; heuristic technique; malware detection toolkit; malware removal toolkit; metaware toolkit; protocol reverse engineering; Databases; Emulation; Malware; Registers; Reverse engineering; Software; Viruses (medical); Computer System Security; Disassembler; Emulator; Malware Reverse Engineering; Virus Detection;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Advanced Communication Technology (ICACT), 2011 13th International Conference on
Conference_Location :
Seoul
ISSN :
1738-9445
Print_ISBN :
978-1-4244-8830-8
Type :
conf
Filename :
5745976
Link To Document :
بازگشت