• DocumentCode
    3062666
  • Title

    Malware Profiler Based on Innovative Behavior-Awareness Technique

  • Author

    Dai, Shih-Yao ; Fyodor, Yarochkin ; Kuo, Sy-Yen ; Wu, Ming-Wei ; Huang, Yennun

  • Author_Institution
    Adv. Res. Center, Inst. for Inf. Ind., Taipei, Taiwan
  • fYear
    2011
  • fDate
    12-14 Dec. 2011
  • Firstpage
    314
  • Lastpage
    319
  • Abstract
    In order to steal valuable data, hackers are uninterrupted research and development new techniques to intrude computer systems. Opposite to hackers, security researchers are uninterrupted analysis and tracking new malicious techniques for protecting sensitive data . There are a lot of existing analyzers can be used to help security researchers to analyze and track new malicious techniques. However, these existing analyzers cannot provide sufficient information to security researchers to perform precise assessment and deep analysis. In this paper, we introduce a behavior-based malicious software profiler, named Holography platform, to assist security researchers to obtain sufficient information. Holography platform analyzes virtualization hardware data, including CPU instructions, CPU registers, memory data and disk data, to obtain high level behavior semantic of all running processes. High level behavior semantic can provide sufficient information to security researchers to perform precise assessment and deep analysis new malicious techniques, such as malicious advertisement attack(malvertising attack).
  • Keywords
    advertising data processing; data analysis; invasive software; program diagnostics; virtualisation; CPU instructions; CPU registers; behavior-based malicious software profiler; computer system intrusion; disk data; holography platform; innovative behavior-awareness technique; malicious advertisement attack; malicious techniques; malvertising attack; memory data; sensitive data protection; uninterrupted analysis; uninterrupted tracking; valuable data stealing; virtualization hardware data analysis; Browsers; HTML; Holography; Malware; Topology; Web pages; complete resource topology; dynamic analysis; malvertising; malware; virtual machine;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Dependable Computing (PRDC), 2011 IEEE 17th Pacific Rim International Symposium on
  • Conference_Location
    Pasadena, CA
  • Print_ISBN
    978-1-4577-2005-5
  • Electronic_ISBN
    978-0-7695-4590-5
  • Type

    conf

  • DOI
    10.1109/PRDC.2011.53
  • Filename
    6133104