DocumentCode :
2226114
Title :
APICapture - A tool for monitoring the behavior of malware
Author :
Miao, Qi-Guang ; Wang, Yun ; Cao, Ying ; Zhang, Xian-Guo ; Liu, Zhong-Lin
Author_Institution :
Sch. of Comput. Sci. & Technol., Xidian Univ., Xi´´an, China
Volume :
4
fYear :
2010
fDate :
20-22 Aug. 2010
Abstract :
Malware is one of the most serious threats to the security of computer systems. Many approaches have been provided and various systems have been designed to detect intrusion from anomalous behavior of system calls which provide the interface between a process and the operating system. Though these techniques look quite effective, a key element seems to be missing - the inclusion and utilization of the system call arguments to create a richer, more valuable signature and analyze the behavior of malware more accurately. Based on this problem, this paper presents APICapture, a tool for monitoring the behavior of malware based on a whole system emulator without changing the system kernel, and automatically recording the system call arguments and some important attributes, for example, the return values, the error statue, etc. Experimental results show that APICapture has a good transparency and accuracy. Transparency means the monitoring method is transparent to target process, making it more difficult to be detected by malware. Moreover, the information obtained can accurately and completely describe the functionality of the malware.
Keywords :
application program interfaces; invasive software; APICapture; computer systems security; malware behavior monitoring; system calls; Monitoring; behavior monitoring; emulator; malware; system calls;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Advanced Computer Theory and Engineering (ICACTE), 2010 3rd International Conference on
Conference_Location :
Chengdu
ISSN :
2154-7491
Print_ISBN :
978-1-4244-6539-2
Type :
conf
DOI :
10.1109/ICACTE.2010.5579452
Filename :
5579452
Link To Document :
بازگشت