• DocumentCode
    2027434
  • Title

    Detecting infection onset with behavior-based policies

  • Author

    Xu, Kui ; Yao, Danfeng ; Ma, Qiang ; Crowell, Alexander

  • Author_Institution
    Dept. of Comput. Sci., Virginia Tech, Blacksburg, VA, USA
  • fYear
    2011
  • fDate
    6-8 Sept. 2011
  • Firstpage
    57
  • Lastpage
    64
  • Abstract
    A major vector of computer infection is through exploiting vulnerable software or design flaws in networked applications such as the browser. Malicious code can be fetched and executed on a victim´s machine without the user´s permission, as in drive-by download (DBD) attacks. In this paper, we describe a new tool called DeWare (standing for Detection of Malware) for detecting the onset of infection delivered through vulnerable applications. DeWare enforces the dependencies between user actions and system events, such as file-system access and process execution. Our tool can be used to provide real time protection of a personal computer, as well as for diagnosing and evaluating untrusted websites for forensic purposes. Our solution demonstrates a usable host-based framework for controlling and enforcing the access of system resources. We perform extensive experimental evaluation, including a user study with 21 participants, thousands of legitimate websites (for testing false alarms), 84 malicious websites in the wild, as well as lab reproduced exploits. Our results show that DeWare is able to correctly distinguish legitimate download events from unauthorized system events with a low false positive rate (<; 1%).
  • Keywords
    Web sites; invasive software; DeWare; Website evaluation; behavior-based policies; computer infection; detection of malware; drive-by download attacks; file-system access; infection onset detection; malicious code; process execution; usable host-based framework; vulnerable software exploitation; Browsers; Kernel; Malware; Monitoring; Semantics;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Network and System Security (NSS), 2011 5th International Conference on
  • Conference_Location
    Milan
  • Print_ISBN
    978-1-4577-0458-1
  • Type

    conf

  • DOI
    10.1109/ICNSS.2011.6059960
  • Filename
    6059960