• DocumentCode
    3735344
  • Title

    Efficient spear-phishing threat detection using hypervisor monitor

  • Author

    Chih-Hung Lin;Chin-Wei Tien;Chih-Wei Chen;Chia-Wei Tien;Hsing-Kuo Pao

  • Author_Institution
    CyberTrust Technology Institute, Institute for Information Industry, Taipei, Taiwan R.O.C.
  • fYear
    2015
  • Firstpage
    299
  • Lastpage
    303
  • Abstract
    In recent years, cyber security threats have become increasingly dangerous. Hackers have fabricated fake emails to spoof specific users into clicking on malicious attachments or URL links in them. This kind of threat is called a spear-phishing attack. Because spear-phishing attacks use unknown exploits to trigger malicious activities, it is difficult to effectively defend against them. Thus, this study focuses on the challenges faced, and we develop a Cloud-threat Inspection Appliance (CIA) system to defend against spear-phishing threats. With the advantages of hardware-assisted virtualization technology, we use the CIA to develop a transparent hypervisor monitor that conceals the presence of the detection engine in the hypervisor kernel. In addition, the CIA also designs a document pre-filtering algorithm to enhance system performance. By inspecting PDF format structures, the proposed CIA was able to filter 77% of PDF attachments and prevent them from all being sent into the hypervisor monitor for deeper analysis. Finally, we tested CIA in real-world scenarios. The hypervisor monitor was shown to be a better anti-evasion sandbox than commercial ones. During 2014, CIA inspected 780,000 mails in a company with 200 user accounts, and found 65 unknown samples that were not detected by commercial anti-virus software.
  • Keywords
    "Portable document format","Monitoring","Virtual machine monitors","Malware","Electronic mail","Virtualization"
  • Publisher
    ieee
  • Conference_Titel
    Security Technology (ICCST), 2015 International Carnahan Conference on
  • Print_ISBN
    978-1-4799-8690-3
  • Electronic_ISBN
    2153-0742
  • Type

    conf

  • DOI
    10.1109/CCST.2015.7389700
  • Filename
    7389700