MalMax: Multi-Aspect Execution for Automated Dynamic Web Server Malware Analysis

MalMax: Multi-Aspect Execution for Automated Dynamic Web Server Malware Analysis
复制标题

MalMax:自动动态 Web 服务器恶意软件分析的多方面执行

DOI:
10.1145/3319535.3363199
复制
发表时间:
2019
期刊:
Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
通讯作者:
Davidson, Jack W.
Davidson, Jack W.
中科院分区:
--
文献类型:
--
作者:
Naderi-Afooshteh, Abbas;Kwon, Yonghwi;Nguyen-Tuong, Anh;Razmjoo-Qalaei, Ali;Zamiri-Gourabi, Mohammad-Reza;Davidson, Jack W.

文献摘要

参考文献

被引文献

相似文献

本文介绍了 MalMax,这是一种用于检测服务器端恶意软件的新颖系统,该系统通常采用复杂的多态规避运行时代码生成技术。当 MalMax 遇到呈现多个可能执行路径(例如,通过谓词和/或动态代码)的执行点时,它会通过在隔离执行环境中沙箱中的代码的反事实执行来探索这些路径。此外,MalMax 的一个独特功能是其协作隔离执行模型,其中一个执行上下文中未解决的工件(例如变量、函数和类)可以​​使用其他执行上下文中的值具体化。这种合作极大地扩大了反事实执行的范围。举例来说,对于 Wordpress,合作可带来 63% 的额外代码覆盖率。反事实执行与协作隔离执行的结合使MalMax能够准确有效地识别恶意行为。使用从商业网络托管公司收集的 PHP Web 应用程序的大型(1 TB)真实世界数据集,我们对 MalMax 进行了广泛的评估。我们通过将 MalMax 检测恶意软件的能力与 VirusTotal(一种聚合了多种不同扫描程序的恶意软件检测器)进行比较来评估 MalMax 的有效性。我们的评估结果表明,MalMax 在揭露复杂的多态恶意软件中的恶意行为方面非常有效。 MalMax 还能够识别 1,485 个恶意软件样本,即使在野外 7 个月后,任何现有最先进的工具也无法检测到这些样本。
This paper presents MalMax, a novel system to detect server-side malware that routinely employ sophisticated polymorphic evasive runtime code generation techniques. When MalMax encounters an execution point that presents multiple possible execution paths (e.g., via predicates and/or dynamic code), it explores these paths through counterfactual execution of code sandboxed within an isolated execution environment. Furthermore, a unique feature of MalMax is its cooperative isolated execution model in which unresolved artifacts (e.g., variables, functions, and classes) within one execution context can be concretized using values from other execution contexts. Such cooperation dramatically amplifies the reach of counterfactual execution. As an example, for Wordpress, cooperation results in 63% additional code coverage. The combination of counterfactual execution and cooperative isolated execution enables MalMax to accurately and effectively identify malicious behavior. Using a large (1 terabyte) real-world dataset of PHP web applications collected from a commercial web hosting company, we performed an extensive evaluation of MalMax. We evaluated the effectiveness of MalMax by comparing its ability to detect malware against VirusTotal, a malware detector that aggregates many diverse scanners. Our evaluation results show that MalMax is highly effective in exposing malicious behavior in complicated polymorphic malware. MalMax was also able to identify 1,485 malware samples that are not detected by any existing state-of-the-art tool, even after 7 months in the wild.
PHP 中动态功能使用的演变
DOI: 10.1109/saner.2015.7081870
发表时间: 2015
期刊: 2015 IEEE 22nd International Conference on Software Analysis, Evolution, and Reengineering (SANER)
影响因子: --
作者:
M. Hills
通讯作者: M. Hills
J-Force:强制执行 JavaScript
DOI: --
发表时间: 2017
期刊: The Web Conference
影响因子: --
作者:
Kyungtae Kim;I. L. Kim;C. Kim;Yonghwi Kwon;Yunhui Zheng;X. Zhang;Dongyan Xu
通讯作者: Dongyan Xu
DOI: 10.1007/978-3-319-11379-1_2
发表时间: 2014-09
期刊: --
影响因子: --
作者:
Zhaoyan Xu;Jialong Zhang;G. Gu;Zhiqiang Lin
通讯作者: Zhaoyan Xu;Jialong Zhang;G. Gu;Zhiqiang Lin
DOI: --
发表时间: 2017
期刊: --
影响因子: --
作者:
Roberto Jordaney;K. Sharad;Santanu Kumar Dash;Zhi Wang;D. Papini;I. Nouretdinov;L. Cavallaro
通讯作者: Roberto Jordaney;K. Sharad;Santanu Kumar Dash;Zhi Wang;D. Papini;I. Nouretdinov;L. Cavallaro
DOI: 10.1145/2976749.2989064
发表时间: 2016-10
期刊: Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security
影响因子: --
作者:
Bo Sun;Akinori Fujino;Tatsuya Mori
通讯作者: Bo Sun;Akinori Fujino;Tatsuya Mori