Title :
Automatic functionality detection in behavior-based IDS
Author :
Nykodym, Tomas ; Skormin, Victor ; Dolgikh, Andrey ; Antonakos, James
Author_Institution :
Binghamton Univ., Binghamton, NY, USA
Abstract :
Detection of malicious functionalities presents an effective way to detect malware in behavior-based IDS. A technology including the utilization of Colored Petri Nets for the generalized description and consequent detection of specific malicious functionalities from system call data has been previously developed, verified and presented. A successful effort was made to neutralize possible attempts to obfuscate this approach. Nevertheless, the approach has two major drawbacks. First, target functionalities have to be initially specified by an expert, which is a time consuming, sometimes subjective and error prone process. Second, the identification of typical functionalities indicative of malicious programs is not generally straightforward and requires reverse engineering and careful study of many instances of malware. Our paper addresses these drawbacks, clearing the way for a full-scale practical application of this technology. We utilized graph mining and graph similarity assessment algorithms for processing system call data resulting in automatic extraction of functionalities from system call data. This enabled us to identify sets of functionalities suggesting software maliciousness and construct a general obfuscation-resilient malware detector. The paper presents the results of the implementation and testing of the described technologies on the computer network testbed.
Keywords :
Petri nets; invasive software; reverse engineering; automatic functionality detection; behavior-based IDS; colored Petri nets; graph mining; graph similarity assessment algorithms; malicious functionalities; malware; reverse engineering; Context; Data models; Feature extraction; Kernel; Malware; Petri nets; Behavior Based IDS; Colored Petri Nets; Signature generation;
Conference_Titel :
MILITARY COMMUNICATIONS CONFERENCE, 2011 - MILCOM 2011
Conference_Location :
Baltimore, MD
Print_ISBN :
978-1-4673-0079-7
DOI :
10.1109/MILCOM.2011.6127482