BinGraph: Discovering mutant malware using hierarchical semantic signatures

BinGraph: Discovering mutant malware using hierarchical semantic signatures
复制标题

BinGraph:使用分层语义签名发现变异恶意软件

DOI:
--
复制
发表时间:
2012
期刊:
International Conference on Malicious and Unwanted Software
影响因子:
--
通讯作者:
Heejo Lee
Heejo Lee
中科院分区:
--
文献类型:
--
作者:
Jonghoon Kwon;Heejo Lee

文献摘要

被引文献

相似文献

在过去十年中,恶意软件的数量急剧上升。增加的主要原因是,新的恶意软件变种可以很容易地使用简单的代码混淆技术产生。一旦应用了模糊处理,恶意软件就可以在保留语义的同时改变它们的语法,并绕过反病毒(AV)扫描程序。因此,恶意软件作者通常使用代码混淆技术来生成变形恶意软件。然而,基于签名的反病毒技术仅限于检测变形恶意软件,因为它们通常基于语法签名匹配。在本文中,我们提出了BinGraph,一个新的机制,准确地发现变形恶意软件。BinGraph利用恶意软件的语义,因为突变的恶意软件只能操纵它们的语法。为此,我们首先从恶意软件中提取API调用,并转换为分层行为图,该行为图基于语义用相同的128个节点表示。之后,我们从分层行为图中提取唯一的子图作为代表特定恶意软件家族常见行为的语义签名。为了评估BinGraph,我们分析了总共827个恶意软件样本,这些样本包括10个恶意软件家族和1,202个良性二进制文件。在恶意软件中,从每个恶意软件家族中随机选择20%的样本用于提取语义特征,其余样本用于评估检测准确性。最后,只有32个子图被选为语义签名。BinGraph以98%的检测准确率发现恶意软件变体。
Malware landscape has been dramatically elevated over the last decade. The main reason of the increase is that new malware variants can be produced easily using simple code obfuscation techniques. Once the obfuscation is applied, the malware can change their syntactics while preserving semantics, and bypass anti-virus (AV) scanners. Malware authors, thus, commonly use the code obfuscation techniques to generate metamorphic malware. Nevertheless, signature based AV techniques are limited to detect the metamorphic malware since they are commonly based on the syntactic signature matching. In this paper, we propose BinGraph, a new mechanism that accurately discovers metamorphic malware. BinGraph leverages the semantics of malware, since the mutant malware is able to manipulate their syntax only. To this end, we first extract API calls from malware and convert to a hierarchical behavior graph that represents with identical 128 nodes based on the semantics. Later, we extract unique subgraphs from the hierarchical behavior graphs as semantic signatures representing common behaviors of a specific malware family. To evaluate BinGraph, we analyzed a total of 827 malware samples that consist of 10 malware families with 1,202 benign binaries. Among the malware, 20% samples randomly chosen from each malware family were used for extracting semantic signatures, and rest of them were used for assessing detection accuracy. Finally, only 32 subgraphs were selected as the semantic signatures. BinGraph discovered malware variants with 98% of detection accuracy.