An empirical analysis of malicious internet banking software behavior

An empirical analysis of malicious internet banking software behavior
复制标题

DOI:
10.1145/2480362.2480704
复制
发表时间:
2013-03
期刊:
--
影响因子:
--
通讯作者:
A. Grégio;Dario Simões Fernandes Filho;V. M. Afonso;P. Geus;Victor Furuse Martins;M. Jino
A. Grégio;Dario Simões Fernandes Filho;V. M. Afonso;P. Geus;Victor Furuse Martins;M. Jino
中科院分区:
其他
文献类型:
--
作者:
A. Grégio;Dario Simões Fernandes Filho;V. M. Afonso;P. Geus;Victor Furuse Martins;M. Jino

文献摘要

被引文献

相似文献

“银行家”是一种特殊类型的恶意软件,其目标是互联网银行用户,主要是为了获取他们的凭据。银行家感染病毒在全球造成数十亿美元的损失。因此,需要更好地了解和发现银行家。由于银行家行为的交互性,获取银行家行为对于当前的动态分析者来说是一项困难的任务。此外,专门用于检测银行家的现有工具通常仅限于特定类型。在这篇文章中,我们提出了BanDIT,一个动态的分析系统,结合视觉分析,网络流量模式匹配和文件系统监控,识别与银行家相关的行为。我们分析了超过1,500个恶意软件样本,以识别那些目标是在线银行的恶意软件,并报告了发现的受损IP和电子邮件地址。我们对他们的行为进行了评估,并显示BanDIT能够在手动标记的银行家样本集中识别98.8%的银行家。
"Bankers" are special types of malware whose targets are Internet banking users, mainly to obtain their credentials. Banker infections cause losses of billions of dollars worldwide. Thus, better understanding and detection of bankers is required. Due to their interactive nature, obtaining bankers' behaviors can be a difficult task for current dynamic analyzers. Also, existing tools specially crafted to detect bankers are usually limited to a specific type. In this article, we propose BanDIT, a dynamic analysis system that identifies behavior related to bankers combining visual analysis, network traffic pattern matching and filesystem monitoring. We analyzed over 1,500 malware samples to identify those whose target were online banks and reported the compromised IP and e-mail addresses found. We present an evaluation of their behavior and show that BanDIT was able to identify 98.8% of bankers in a manually labeled banker samples set.