The Experts below are selected from a list of 441 Experts worldwide ranked by ideXlab platform

Giovanni Vigna - One of the best experts on this subject based on the ideXlab platform.

  • MalGene : Automatic Extraction of Malware Analysis Evasion Signature
    CCS, 2015
    Co-Authors: Dhilung Kirat, Giovanni Vigna
    Abstract:

    Automated dynamic Malware analysis is a common approach for detecting malicious software. However, many Malware samples identify the presence of the analysis environment and evade detection by not performing any malicious activity. Recently, an approach to the automated detection of such evasive Malware was proposed. In this approach, a Malware sample is analyzed in multiple analysis environments, including a bare-metal environment, and its various behaviors are compared. Malware whose behavior deviates substantially is identified as evasive Malware. However, a Malware Analyst still needs to re-analyze the identified evasive sample to understand the technique used for evasion. Different tools are available to help Malware Analysts in this process. However, these tools in practice require considerable manual input along with auxiliary information. This manual process is resource-intensive and not scalable. In this paper, we present MalGene, an automated technique for extracting analysis evasion signatures. MalGene leverages algorithms borrowed from bioinformatics to automatically locate evasive behavior in system call sequences. Data flow analysis and data mining techniques are used to identify call events and data comparison events used to perform the evasion. These events are used to construct a succinct evasion signature, which can be used by an Analyst to quickly understand evasions. Finally, evasive Malware samples are clustered based on their underlying evasive techniques. We evaluated our techniques on 2810 evasive samples. We were able to automatically extract their analysis evasion signatures and group them into 78 similar evasion techniques.

  • ACM Conference on Computer and Communications Security - MalGene: Automatic Extraction of Malware Analysis Evasion Signature
    Proceedings of the 22nd ACM SIGSAC Conference on Computer and Communications Security - CCS '15, 2015
    Co-Authors: Kirat Dhilung Hang, Giovanni Vigna
    Abstract:

    Automated dynamic Malware analysis is a common approach for detecting malicious software. However, many Malware samples identify the presence of the analysis environment and evade detection by not performing any malicious activity. Recently, an approach to the automated detection of such evasive Malware was proposed. In this approach, a Malware sample is analyzed in multiple analysis environments, including a bare-metal environment, and its various behaviors are compared. Malware whose behavior deviates substantially is identified as evasive Malware. However, a Malware Analyst still needs to re-analyze the identified evasive sample to understand the technique used for evasion. Different tools are available to help Malware Analysts in this process. However, these tools in practice require considerable manual input along with auxiliary information. This manual process is resource-intensive and not scalable. In this paper, we present MalGene, an automated technique for extracting analysis evasion signatures. MalGene leverages algorithms borrowed from bioinformatics to automatically locate evasive behavior in system call sequences. Data flow analysis and data mining techniques are used to identify call events and data comparison events used to perform the evasion. These events are used to construct a succinct evasion signature, which can be used by an Analyst to quickly understand evasions. Finally, evasive Malware samples are clustered based on their underlying evasive techniques. We evaluated our techniques on 2810 evasive samples. We were able to automatically extract their analysis evasion signatures and group them into 78 similar evasion techniques.

Shauna Policicchio - One of the best experts on this subject based on the ideXlab platform.

  • Bulk Analysis of Malicious PDF Documents
    2015
    Co-Authors: Shauna Policicchio
    Abstract:

    From 2007 onward, the PDF document has proven to be a successful vector for Malware infections, making up 80% of all exploits found by Cisco ScanSafe in 2009 [1]. Creating new PDF documents is very easy and the volume of PDF documents identified as malicious has grown beyond the capabilities of security researchers to analyze by hand. The solution proposed by this thesis is to automatically extract features from the PDF documents to group and classify them, so that similar Malware may be identified without manual analysis, thus reducing the workload of the Malware Analyst. These features may also be studied to identify trends within the PDF documents, such as similar exploits or obfuscation techniques. Our results show that the object graph structure of the PDF document is an effective way to create an initial grouping of malicious PDF documents. Finding similarities in PDF documents reveals further information about a data set. In our first case study, we examine the entire data set to identify large groups of similar PDF documents and make conjectures about their origins. In our second case study, we use a PDF document of known origin to find similar PDF documents within a data set. Through the two case studies, we were able to identify 50.3% of our data set with very little manual analysis of the malicious PDF documents.

P. R. L. Eswari - One of the best experts on this subject based on the ideXlab platform.

  • Entropy and n-gram Analysis of Malicious PDF Documents
    International journal of engineering research and technology, 2013
    Co-Authors: Himanshu Pareek, P. R. L. Eswari
    Abstract:

    Malware is a persistent problem in field of computer security and its complexity has increased multiple folds in past decade. In past few years malicious documents attacks have emerged as preferred method to bypass the security of a host computer. This work assumes that such kind of exploits do not carry any important information and hence should not be highly random. However use of randomness is not a deterministic approach for detection of malicious code but gives a useful indication to Malware Analyst. This research report presents two discrete analyses of malicious PDF documents. One is entropy and other being n-gram term frequency.

Cabuya Padilla, Diego Edison - One of the best experts on this subject based on the ideXlab platform.

  • Building Malware classificators usable by State security agencies
    2018
    Co-Authors: Useche Peláez, David Esteban, Díaz López, Daniel Orlando, Sepúlveda Alzate Daniela, Cabuya Padilla, Diego Edison
    Abstract:

    El sandboxing ha sido usado de manera regular para analizar muestras de software y determinar si estas contienen propiedades o comportamientos sospechosos. A pesar de que el sandboxing es una técnica poderosa para desarrollar análisis de Malware, esta requiere que un analista de Malware desarrolle un análisis riguroso de los resultados para determinar la naturaleza de la muestra: goodware o Malware. Este artículo propone dos modelos de aprendizaje automáticos capaces de clasificar muestras con base a un análisis de firmas o permisos extraídos por medio de Cuckoo sandbox, Androguard y VirusTotal. En este artículo también se presenta una propuesta de arquitectura de centinela IoT que protege dispositivos IoT, usando uno de los modelos de aprendizaje automáticos desarrollados anteriormente. Finalmente, diferentes enfoques y perspectivas acerca del uso de sandboxing y aprendizaje automático por parte de agencias de seguridad del Estado también son aportados.Sandboxing has been used regularly to analyze software samples and determine if these contain suspicious properties or behaviors. Even if sandboxing is a powerful technique to perform Malware analysis, it requires that a Malware Analyst performs a rigorous analysis of the results to determine the nature of the sample: goodware or Malware. This paper proposes two machine learning models able to classify samples based on signatures and permissions obtained through Cuckoo sandbox, Androguard and VirusTotal. The developed models are also tested obtaining an acceptable percentage of correctly classified samples, being in this way useful tools for a Malware Analyst. A proposal of architecture for an IoT sentinel that uses one of the developed machine learning model is also showed. Finally, different approaches, perspectives, and challenges about the use of sandboxing and machine learning by security teams in State security agencies are also shared

  • Construcción de clasificadores de Malware para agencias de seguridad del Estado
    'Universidad Santo Tomas', 2018
    Co-Authors: Useche Peláez, David Esteban, Díaz López, Daniel Orlando, Sepúlveda Alzate Daniela, Cabuya Padilla, Diego Edison
    Abstract:

    El sandboxing ha sido usado de manera regular para analizar muestras de software y determinar si estas contienen propiedades o comportamientos sospechosos. A pesar de que el sandboxing es una técnica poderosa para desarrollar análisis de Malware, esta requiere que un analista de Malware desarrolle un análisis riguroso de los resultados para determinar la naturaleza de la muestra: goodware o Malware. Este artículo propone dos modelos de aprendizaje automáticos capaces de clasificar muestras con base a un análisis de firmas o permisos extraídos por medio de Cuckoo sandbox, Androguard y VirusTotal. En este artículo también se presenta una propuesta de arquitectura de centinela IoT que protege dispositivos IoT, usando uno de los modelos de aprendizaje automáticos desarrollados anteriormente. Finalmente, diferentes enfoques y perspectivas acerca del uso de sandboxing y aprendizaje automático por parte de agencias de seguridad del Estado también son aportados.Sandboxing has been used regularly to analyze software samples and determine if these contain suspicious properties or behaviors. Even if sandboxing is a powerful technique to perform Malware analysis, it requires that a Malware Analyst performs a rigorous analysis of the results to determine the nature of the sample: goodware or Malware. This paper proposes two machine learning models able to classify samples based on signatures and permissions obtained through Cuckoo sandbox, Androguard and VirusTotal. The developed models are also tested obtaining an acceptable percentage of correctly classified samples, being in this way useful tools for a Malware Analyst. A proposal of architecture for an IoT sentinel that uses one of the developed machine learning model is also showed. Finally, different approaches, perspectives, and challenges about the use of sandboxing and machine learning by security teams in State security agencies are also shared

Dhilung Kirat - One of the best experts on this subject based on the ideXlab platform.

  • MalGene : Automatic Extraction of Malware Analysis Evasion Signature
    CCS, 2015
    Co-Authors: Dhilung Kirat, Giovanni Vigna
    Abstract:

    Automated dynamic Malware analysis is a common approach for detecting malicious software. However, many Malware samples identify the presence of the analysis environment and evade detection by not performing any malicious activity. Recently, an approach to the automated detection of such evasive Malware was proposed. In this approach, a Malware sample is analyzed in multiple analysis environments, including a bare-metal environment, and its various behaviors are compared. Malware whose behavior deviates substantially is identified as evasive Malware. However, a Malware Analyst still needs to re-analyze the identified evasive sample to understand the technique used for evasion. Different tools are available to help Malware Analysts in this process. However, these tools in practice require considerable manual input along with auxiliary information. This manual process is resource-intensive and not scalable. In this paper, we present MalGene, an automated technique for extracting analysis evasion signatures. MalGene leverages algorithms borrowed from bioinformatics to automatically locate evasive behavior in system call sequences. Data flow analysis and data mining techniques are used to identify call events and data comparison events used to perform the evasion. These events are used to construct a succinct evasion signature, which can be used by an Analyst to quickly understand evasions. Finally, evasive Malware samples are clustered based on their underlying evasive techniques. We evaluated our techniques on 2810 evasive samples. We were able to automatically extract their analysis evasion signatures and group them into 78 similar evasion techniques.