Cubismo: decloaking server-side malware via cubist program analysis

Cubismo: decloaking server-side malware via cubist program analysis
复制标题

Cubismo:通过立体程序分析解密服务器端恶意软件

DOI:
10.1145/3359789.3359821
复制
发表时间:
2019
期刊:
Proceedings of the 35th Annual Computer Security Applications Conference
影响因子:
--
通讯作者:
Davidson, Jack W.
Davidson, Jack W.
中科院分区:
--
文献类型:
--
作者:
Naderi-Afooshteh, Abbas;Kwon, Yonghwi;Nguyen-Tuong, Anh;Bagheri-Marzijarani, Mandana;Davidson, Jack W.

文献摘要

参考文献

被引文献

相似文献

用动态语言(如PHP)编写的恶意软件通常使用诸如混淆方案和回避技巧等反分析技术来躲避检测。最重要的是,攻击者使用自动恶意软件创建工具来创建大量变体,几乎不需要手动操作。本文提出了一个名为CuBismo的系统来解决这一紧迫问题。它处理潜在的恶意文件并揭开其混淆的面纱,将隐藏的恶意代码暴露到多个文件中。产生的文件可以被现有的恶意软件检测工具扫描,从而导致更高的检测机会。CuBismo通过反事实地探测可疑程序的所有可执行语句来实现改进的检测,以识破复杂的多态、变形和混淆技术并揭露任何恶意软件。我们对从商业网络托管公司收集的真实数据集进行的评估表明,CuBismo在剖析具有多层混淆的复杂变形恶意软件方面非常有效。特别是,它使VirusTotal能够检测到56个零日恶意软件样本中的53个,而这些样本以前是无法检测到的。
Malware written in dynamic languages such as PHP routinely employ anti-analysis techniques such as obfuscation schemes and evasive tricks to avoid detection. On top of that, attackers use automated malware creation tools to create numerous variants with little to no manual effort.This paper presents a system called Cubismo to solve this pressing problem. It processes potentially malicious files and decloaks their obfuscations, exposing the hidden malicious code into multiple files. The resulting files can be scanned by existing malware detection tools, leading to a much higher chance of detection. Cubismo achieves improved detection by exploring all executable statements of a suspect program counterfactually to see through complicated polymorphism, metamorphism and, obfuscation techniques and expose any malware.Our evaluation on a real-world data set collected from a commercial web hosting company shows that Cubismo is highly effective in dissecting sophisticated metamorphic malware with multiple layers of obfuscation. In particular, it enables VirusTotal to detect 53 out of 56 zero-day malware samples in the wild, which were previously undetectable.
PHP 中动态功能使用的演变
DOI: 10.1109/saner.2015.7081870
发表时间: 2015
期刊: 2015 IEEE 22nd International Conference on Software Analysis, Evolution, and Reengineering (SANER)
影响因子: --
作者:
M. Hills
通讯作者: M. Hills
J-Force:强制执行 JavaScript
DOI: --
发表时间: 2017
期刊: The Web Conference
影响因子: --
作者:
Kyungtae Kim;I. L. Kim;C. Kim;Yonghwi Kwon;Yunhui Zheng;X. Zhang;Dongyan Xu
通讯作者: Dongyan Xu
DOI: --
发表时间: 2017
期刊: --
影响因子: --
作者:
Roberto Jordaney;K. Sharad;Santanu Kumar Dash;Zhi Wang;D. Papini;I. Nouretdinov;L. Cavallaro
通讯作者: Roberto Jordaney;K. Sharad;Santanu Kumar Dash;Zhi Wang;D. Papini;I. Nouretdinov;L. Cavallaro
基于签名的恶意软件检测已失效
DOI: --
发表时间: 2017
期刊:
影响因子: --
作者:
S. Sim;Yiting Yu;C. H. Lin;R. K. M. Karuturi;V. Wuthiekanun;A. Tuanyok;H. Chua;C. Ong;Sivalingam Suppiah Paramalingam;Gladys Tan;L. Tang;G. Lau;E. Ooi;D. Woods;E. Feil;Sharon J. Peacock;Sharon J. Peacock;Patrick Tan;Patrick Tan
通讯作者: Patrick Tan
DOI: 10.1145/2976749.2989064
发表时间: 2016-10
期刊: Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security
影响因子: --
作者:
Bo Sun;Akinori Fujino;Tatsuya Mori
通讯作者: Bo Sun;Akinori Fujino;Tatsuya Mori