MalMax: Multi-Aspect Execution for Automated Dynamic Web Server Malware Analysis
MalMax: Multi-Aspect Execution for Automated Dynamic Web Server Malware Analysis
复制标题
MalMax:自动动态 Web 服务器恶意软件分析的多方面执行
DOI:
10.1145/3319535.3363199
复制
发表时间:
2019
期刊:
影响因子:
--
通讯作者:
Davidson, Jack W.
中科院分区:
文献类型:
--
作者:
Naderi-Afooshteh, Abbas;Kwon, Yonghwi;Nguyen-Tuong, Anh;Razmjoo-Qalaei, Ali;Zamiri-Gourabi, Mohammad-Reza;Davidson, Jack W.
This paper presents MalMax, a novel system to detect server-side malware that routinely employ sophisticated polymorphic evasive runtime code generation techniques. When MalMax encounters an execution point that presents multiple possible execution paths (e.g., via predicates and/or dynamic code), it explores these paths through counterfactual execution of code sandboxed within an isolated execution environment. Furthermore, a unique feature of MalMax is its cooperative isolated execution model in which unresolved artifacts (e.g., variables, functions, and classes) within one execution context can be concretized using values from other execution contexts. Such cooperation dramatically amplifies the reach of counterfactual execution. As an example, for Wordpress, cooperation results in 63% additional code coverage. The combination of counterfactual execution and cooperative isolated execution enables MalMax to accurately and effectively identify malicious behavior. Using a large (1 terabyte) real-world dataset of PHP web applications collected from a commercial web hosting company, we performed an extensive evaluation of MalMax. We evaluated the effectiveness of MalMax by comparing its ability to detect malware against VirusTotal, a malware detector that aggregates many diverse scanners. Our evaluation results show that MalMax is highly effective in exposing malicious behavior in complicated polymorphic malware. MalMax was also able to identify 1,485 malware samples that are not detected by any existing state-of-the-art tool, even after 7 months in the wild.
登录
查看更多内容
DOI:
10.1109/saner.2015.7081870
发表时间:
2015
期刊:
2015 IEEE 22nd International Conference on Software Analysis, Evolution, and Reengineering (SANER)
影响因子:
--
作者:
M. Hills
通讯作者:
M. Hills
DOI:
--
发表时间:
2017
期刊:
The Web Conference
影响因子:
--
作者:
Kyungtae Kim;I. L. Kim;C. Kim;Yonghwi Kwon;Yunhui Zheng;X. Zhang;Dongyan Xu
通讯作者:
Dongyan Xu
DOI:
10.1007/978-3-319-11379-1_2
发表时间:
2014-09
期刊:
--
影响因子:
--
作者:
Zhaoyan Xu;Jialong Zhang;G. Gu;Zhiqiang Lin
通讯作者:
Zhaoyan Xu;Jialong Zhang;G. Gu;Zhiqiang Lin
DOI:
--
发表时间:
2017
期刊:
--
影响因子:
--
作者:
Roberto Jordaney;K. Sharad;Santanu Kumar Dash;Zhi Wang;D. Papini;I. Nouretdinov;L. Cavallaro
通讯作者:
Roberto Jordaney;K. Sharad;Santanu Kumar Dash;Zhi Wang;D. Papini;I. Nouretdinov;L. Cavallaro
DOI:
10.1145/2976749.2989064
发表时间:
2016-10
期刊:
Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
作者:
Bo Sun;Akinori Fujino;Tatsuya Mori
通讯作者:
Bo Sun;Akinori Fujino;Tatsuya Mori