DocumentCode
3062666
Title
Malware Profiler Based on Innovative Behavior-Awareness Technique
Author
Dai, Shih-Yao ; Fyodor, Yarochkin ; Kuo, Sy-Yen ; Wu, Ming-Wei ; Huang, Yennun
Author_Institution
Adv. Res. Center, Inst. for Inf. Ind., Taipei, Taiwan
fYear
2011
fDate
12-14 Dec. 2011
Firstpage
314
Lastpage
319
Abstract
In order to steal valuable data, hackers are uninterrupted research and development new techniques to intrude computer systems. Opposite to hackers, security researchers are uninterrupted analysis and tracking new malicious techniques for protecting sensitive data . There are a lot of existing analyzers can be used to help security researchers to analyze and track new malicious techniques. However, these existing analyzers cannot provide sufficient information to security researchers to perform precise assessment and deep analysis. In this paper, we introduce a behavior-based malicious software profiler, named Holography platform, to assist security researchers to obtain sufficient information. Holography platform analyzes virtualization hardware data, including CPU instructions, CPU registers, memory data and disk data, to obtain high level behavior semantic of all running processes. High level behavior semantic can provide sufficient information to security researchers to perform precise assessment and deep analysis new malicious techniques, such as malicious advertisement attack(malvertising attack).
Keywords
advertising data processing; data analysis; invasive software; program diagnostics; virtualisation; CPU instructions; CPU registers; behavior-based malicious software profiler; computer system intrusion; disk data; holography platform; innovative behavior-awareness technique; malicious advertisement attack; malicious techniques; malvertising attack; memory data; sensitive data protection; uninterrupted analysis; uninterrupted tracking; valuable data stealing; virtualization hardware data analysis; Browsers; HTML; Holography; Malware; Topology; Web pages; complete resource topology; dynamic analysis; malvertising; malware; virtual machine;
fLanguage
English
Publisher
ieee
Conference_Titel
Dependable Computing (PRDC), 2011 IEEE 17th Pacific Rim International Symposium on
Conference_Location
Pasadena, CA
Print_ISBN
978-1-4577-2005-5
Electronic_ISBN
978-0-7695-4590-5
Type
conf
DOI
10.1109/PRDC.2011.53
Filename
6133104
Link To Document