• DocumentCode
    598565
  • Title

    Using Infection Markers as a Vaccine against Malware Attacks

  • Author

    Wichmann, Arne ; Gerhards-Padilla, Elmar

  • Author_Institution
    Fraunhofer FKIE, Bonn, Germany
  • fYear
    2012
  • fDate
    20-23 Nov. 2012
  • Firstpage
    737
  • Lastpage
    742
  • Abstract
    Malware is used by criminals for financial gains, espionage and sabotage, and their code and evasion techniques become increasingly complex and sophisticated. This means it takes longer for security researchers to analyse a malware and develop detection and removal routines, increasing the danger of critical systems becoming infected. In order to prevent multiple infections of the same system, malware often uses infection markers to mark a system as already infected. In this paper, we introduce the concept of using these markers to vaccinate systems against infections by a specific malware family. We discuss the characteristics of infection markers and develop a taxonomy of marker types. Then, we present a framework capable of classifying the infection marker used by a malware sample, and which can in most cases automatically extract the marker and generate a vaccination program. Evaluation with a large corpus of malware samples shows that for almost all malware that uses an infection marker, a vaccination program can be generated without the need of a human expert. Two case studies with prominent malware samples, Sality and Conficker, further show the potential of this approach.
  • Keywords
    automatic programming; computer crime; financial data processing; invasive software; pattern classification; Conficker; Sality; automatic marker extraction; critical system; espionage; evasion techniques; financial gains; infection marker classification; malware attack; malware sample; sabotage; taxonomy; vaccinate system; vaccination program generation; Computers; Grippers; Heuristic algorithms; Malware; Software; Taxonomy; Vaccines; intrusion prevention; malware;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Green Computing and Communications (GreenCom), 2012 IEEE International Conference on
  • Conference_Location
    Besancon
  • Print_ISBN
    978-1-4673-5146-1
  • Type

    conf

  • DOI
    10.1109/GreenCom.2012.121
  • Filename
    6468401