• DocumentCode
    58890
  • Title

    Behavioral Malware Detection in Delay Tolerant Networks

  • Author

    Wei Peng ; Feng Li ; Xukai Zou ; Jie Wu

  • Author_Institution
    Dept. of Comput. & Inf. Sci., Indiana Univ.-Purdue Univ. Indianapolis, Indianapolis, IN, USA
  • Volume
    25
  • Issue
    1
  • fYear
    2014
  • fDate
    Jan. 2014
  • Firstpage
    53
  • Lastpage
    63
  • Abstract
    The delay-tolerant-network (DTN) model is becoming a viable communication alternative to the traditional infrastructural model for modern mobile consumer electronics equipped with short-range communication technologies such as Bluetooth, NFC, and Wi-Fi Direct. Proximity malware is a class of malware that exploits the opportunistic contacts and distributed nature of DTNs for propagation. Behavioral characterization of malware is an effective alternative to pattern matching in detecting malware, especially when dealing with polymorphic or obfuscated malware. In this paper, we first propose a general behavioral characterization of proximity malware which based on naive Bayesian model, which has been successfully applied in non-DTN settings such as filtering email spams and detecting botnets. We identify two unique challenges for extending Bayesian malware detection to DTNs ("insufficient evidence versus evidence collection risk" and "filtering false evidence sequentially and distributedly"), and propose a simple yet effective method, look ahead, to address the challenges. Furthermore, we propose two extensions to look ahead, dogmatic filtering, and adaptive look ahead, to address the challenge of "malicious nodes sharing false evidence." Real mobile network traces are used to verify the effectiveness of the proposed methods.
  • Keywords
    Bayes methods; delay tolerant networks; filtering theory; invasive software; mobile radio; Bayesian malware detection; DTN model; adaptive look ahead; behavioral characterization; delay-tolerant-network model; dogmatic filtering; modern mobile consumer electronics; naive Bayesian model; obfuscated malware; polymorphic malware; proximity malware; short-range communication technologies; Aging; Bayesian methods; Bluetooth; Equations; Malware; Mathematical model; Silicon; Bayesian filtering; Delay-tolerant networks; behavioral malware characterization; proximity malware;
  • fLanguage
    English
  • Journal_Title
    Parallel and Distributed Systems, IEEE Transactions on
  • Publisher
    ieee
  • ISSN
    1045-9219
  • Type

    jour

  • DOI
    10.1109/TPDS.2013.27
  • Filename
    6463391