An empirical analysis of malicious internet banking software behavior
An empirical analysis of malicious internet banking software behavior
复制标题
DOI:
10.1145/2480362.2480704
复制
发表时间:
2013-03
期刊:
影响因子:
--
通讯作者:
A. Grégio;Dario Simões Fernandes Filho;V. M. Afonso;P. Geus;Victor Furuse Martins;M. Jino
中科院分区:
文献类型:
--
作者:
A. Grégio;Dario Simões Fernandes Filho;V. M. Afonso;P. Geus;Victor Furuse Martins;M. Jino
"Bankers" are special types of malware whose targets are Internet banking users, mainly to obtain their credentials. Banker infections cause losses of billions of dollars worldwide. Thus, better understanding and detection of bankers is required. Due to their interactive nature, obtaining bankers' behaviors can be a difficult task for current dynamic analyzers. Also, existing tools specially crafted to detect bankers are usually limited to a specific type. In this article, we propose BanDIT, a dynamic analysis system that identifies behavior related to bankers combining visual analysis, network traffic pattern matching and filesystem monitoring. We analyzed over 1,500 malware samples to identify those whose target were online banks and reported the compromised IP and e-mail addresses found. We present an evaluation of their behavior and show that BanDIT was able to identify 98.8% of bankers in a manually labeled banker samples set.