• DocumentCode
    2764083
  • Title

    Building malware infection trees

  • Author

    Morales, Jose Andre ; Main, Michael ; Luo, Weiliang ; Xu, Shouhuai ; Sandhu, Ravi

  • Author_Institution
    Software Eng. Inst., Carnegie Mellon Univ., Pittsburgh, PA, USA
  • fYear
    2011
  • fDate
    18-19 Oct. 2011
  • Firstpage
    50
  • Lastpage
    57
  • Abstract
    Dynamic analysis of malware is an ever evolving and challenging task. A malware infection tree (MiT) can assist in analysis by identifying processes and files related to a specific malware sample. In this paper we propose an abstract approach to building a comprehensive MiT based on rules describing execution events essential to malware infection strategies of files and processes. The MiT is built using strong and weak bonds between processes and files which are based on transitivity of information and creator/created relationships. The abstract approach facilitates usage on any operating system platform. We implement the rules on the Windows Vista operating system using a custom built tool named MiTCoN which was used in a small scale analysis and infection tree creation of a diverse set of 5800 known malware samples. Results analysis revealed a significant occurrent of our rules within a very short span of time. We demonstrate our rule set can effectively and efficiently build infection trees linking all related processes and files of a specific malware sample with no false positives. We also tested the possible usability of a MiT in disinfecting a system which yielded a 100% success rate.
  • Keywords
    invasive software; operating systems (computers); tree data structures; MiTCoN; Windows Vista operating system; abstract approach; custom built tool; dynamic malware analysis; malware infection trees; Buildings; Educational institutions; Image edge detection; Kernel; Malware;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Malicious and Unwanted Software (MALWARE), 2011 6th International Conference on
  • Conference_Location
    Fajardo
  • Print_ISBN
    978-1-4673-0031-5
  • Type

    conf

  • DOI
    10.1109/MALWARE.2011.6112326
  • Filename
    6112326