DocumentCode :
588954
Title :
Osiris: A Malware Behavior Capturing System Implemented at Virtual Machine Monitor Layer
Author :
Ying Cao ; Jiachen Liu ; Qiguang Miao ; Weisheng Li
Author_Institution :
Sch. of Comput. Sci., Xidian Univ., Xi´an, China
fYear :
2012
fDate :
17-18 Nov. 2012
Firstpage :
534
Lastpage :
538
Abstract :
Capturing behavior of malware is one of the essential prerequisites for dynamic malware analysis. In this paper, we study and design a system called Osiris, which makes use of virtual machine technique to capture malware behavior. In particularly, we monitor Windows API calls invoked by the process under analysis (or target program) to rebuild its behaviors. The monitor is implemented at the virtual machine manager layer rather than inside the Guest OS, which is an innovation compared to other available methods. Qemu, an open-source system emulator, is used as the emulator component of Osiris. By modifying Qemu´s translation process, an API analysis framework is inserted to intercept API calls. Besides this, Osiris also collects security relevant OS kernel data directly from virtual memory for further analysis. Osiris has advantages over previous systems in that it requires no complex analysis environment and does not interfere the execution of target programs. It overcomes the deficiencies previous ones employed that the information collected is incomplete and imprecise. These features make Osiris an ideal tool for automatic malware analysis. It can provide fine data for behavior-based malware detection.
Keywords :
application program interfaces; invasive software; operating system kernels; public domain software; virtual machines; API analysis framework; OS kernel data; Osiris; Qemu; Windows API calls; behavior-based malware detection; dynamic malware analysis; guest OS; malware behavior capturing system; open-source system emulator; virtual machine monitor layer; Educational institutions; Kernel; Malware; Monitoring; Process control; Virtual machining; API interception; dynamic analysis; process recognizing; virtual machine monitor;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Computational Intelligence and Security (CIS), 2012 Eighth International Conference on
Conference_Location :
Guangzhou
Print_ISBN :
978-1-4673-4725-9
Type :
conf
DOI :
10.1109/CIS.2012.126
Filename :
6406077
Link To Document :
بازگشت