• DocumentCode
    588954
  • Title

    Osiris: A Malware Behavior Capturing System Implemented at Virtual Machine Monitor Layer

  • Author

    Ying Cao ; Jiachen Liu ; Qiguang Miao ; Weisheng Li

  • Author_Institution
    Sch. of Comput. Sci., Xidian Univ., Xi´an, China
  • fYear
    2012
  • fDate
    17-18 Nov. 2012
  • Firstpage
    534
  • Lastpage
    538
  • Abstract
    Capturing behavior of malware is one of the essential prerequisites for dynamic malware analysis. In this paper, we study and design a system called Osiris, which makes use of virtual machine technique to capture malware behavior. In particularly, we monitor Windows API calls invoked by the process under analysis (or target program) to rebuild its behaviors. The monitor is implemented at the virtual machine manager layer rather than inside the Guest OS, which is an innovation compared to other available methods. Qemu, an open-source system emulator, is used as the emulator component of Osiris. By modifying Qemu´s translation process, an API analysis framework is inserted to intercept API calls. Besides this, Osiris also collects security relevant OS kernel data directly from virtual memory for further analysis. Osiris has advantages over previous systems in that it requires no complex analysis environment and does not interfere the execution of target programs. It overcomes the deficiencies previous ones employed that the information collected is incomplete and imprecise. These features make Osiris an ideal tool for automatic malware analysis. It can provide fine data for behavior-based malware detection.
  • Keywords
    application program interfaces; invasive software; operating system kernels; public domain software; virtual machines; API analysis framework; OS kernel data; Osiris; Qemu; Windows API calls; behavior-based malware detection; dynamic malware analysis; guest OS; malware behavior capturing system; open-source system emulator; virtual machine monitor layer; Educational institutions; Kernel; Malware; Monitoring; Process control; Virtual machining; API interception; dynamic analysis; process recognizing; virtual machine monitor;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computational Intelligence and Security (CIS), 2012 Eighth International Conference on
  • Conference_Location
    Guangzhou
  • Print_ISBN
    978-1-4673-4725-9
  • Type

    conf

  • DOI
    10.1109/CIS.2012.126
  • Filename
    6406077