Obfuscation Revealed: Leveraging Electromagnetic Signals for Obfuscated Malware Classification

Obfuscation Revealed: Leveraging Electromagnetic Signals for Obfuscated Malware Classification
复制标题

混淆揭秘:利用电磁信号进行混淆恶意软件分类

DOI:
10.1145/3485832.3485894
复制
发表时间:
2021
期刊:
Proceedings of the 37th Annual Computer Security Applications Conference
影响因子:
--
通讯作者:
Annelie Heuser
Annelie Heuser
中科院分区:
--
文献类型:
--
作者:
Duy;Damien Marion;Matthieu Mastio;Annelie Heuser

文献摘要

被引文献

相似文献

物联网(IoT)由数量和复杂性呈指数级增长的设备组成。它们使用许多定制的固件和硬件,而不考虑安全问题,这使它们成为网络犯罪分子,特别是恶意软件作者的目标。我们将提出一种新的方法,使用侧通道信息来识别针对该设备的威胁类型。使用我们的方法,恶意软件分析员能够获得有关恶意软件类型和身份的准确知识,即使存在可能阻止静态或符号二进制分析的混淆技术也是如此。我们记录了来自物联网设备的100,000个测量痕迹,这些设备受到各种野生恶意软件样本和真实的良性活动的感染。我们的方法不需要对目标设备进行任何修改。因此,它可以独立于可用的资源进行部署,而不会产生任何开销。此外,我们的方法具有很难被恶意软件作者检测和规避的优点。在我们的实验中,我们能够预测三种通用恶意软件类型(和一种良性类别),准确率为99.82%。更重要的是,我们的结果表明,我们能够在培训阶段使用看不见的混淆技术对更改的恶意软件样本进行分类,并确定对二进制文件应用了何种混淆,这使得我们的方法对恶意软件分析师特别有用。
The Internet of Things (IoT) is constituted of devices that are exponentially growing in number and in complexity. They use numerous customized firmware and hardware, without taking into consideration security issues, which make them a target for cybercriminals, especially malware authors. We will present a novel approach of using side channel information to identify the kinds of threats that are targeting the device. Using our approach, a malware analyst is able to obtain precise knowledge about malware type and identity, even in the presence of obfuscation techniques which may prevent static or symbolic binary analysis. We recorded 100,000 measurement traces from an IoT device infected by various in-the-wild malware samples and realistic benign activity. Our method does not require any modification on the target device. Thus, it can be deployed independently from the resources available without any overhead. Moreover, our approach has the advantage that it can hardly be detected and evaded by the malware authors. In our experiments, we were able to predict three generic malware types (and one benign class) with an accuracy of 99.82%. Even more, our results show that we are able to classify altered malware samples with unseen obfuscation techniques during the training phase, and to determine what kind of obfuscations were applied to the binary, which makes our approach particularly useful for malware analysts.