DocumentCode :
2027434
Title :
Detecting infection onset with behavior-based policies
Author :
Xu, Kui ; Yao, Danfeng ; Ma, Qiang ; Crowell, Alexander
Author_Institution :
Dept. of Comput. Sci., Virginia Tech, Blacksburg, VA, USA
fYear :
2011
fDate :
6-8 Sept. 2011
Firstpage :
57
Lastpage :
64
Abstract :
A major vector of computer infection is through exploiting vulnerable software or design flaws in networked applications such as the browser. Malicious code can be fetched and executed on a victim´s machine without the user´s permission, as in drive-by download (DBD) attacks. In this paper, we describe a new tool called DeWare (standing for Detection of Malware) for detecting the onset of infection delivered through vulnerable applications. DeWare enforces the dependencies between user actions and system events, such as file-system access and process execution. Our tool can be used to provide real time protection of a personal computer, as well as for diagnosing and evaluating untrusted websites for forensic purposes. Our solution demonstrates a usable host-based framework for controlling and enforcing the access of system resources. We perform extensive experimental evaluation, including a user study with 21 participants, thousands of legitimate websites (for testing false alarms), 84 malicious websites in the wild, as well as lab reproduced exploits. Our results show that DeWare is able to correctly distinguish legitimate download events from unauthorized system events with a low false positive rate (<; 1%).
Keywords :
Web sites; invasive software; DeWare; Website evaluation; behavior-based policies; computer infection; detection of malware; drive-by download attacks; file-system access; infection onset detection; malicious code; process execution; usable host-based framework; vulnerable software exploitation; Browsers; Kernel; Malware; Monitoring; Semantics;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Network and System Security (NSS), 2011 5th International Conference on
Conference_Location :
Milan
Print_ISBN :
978-1-4577-0458-1
Type :
conf
DOI :
10.1109/ICNSS.2011.6059960
Filename :
6059960
Link To Document :
بازگشت