Title :
Multi-channel Change-Point Malware Detection
Author :
Canzanese, Raymond ; Kam, Moshe ; Mancoridis, Spiros
Author_Institution :
Dept. of Electr. & Comput. Eng., Drexel Univ., Philadelphia, PA, USA
Abstract :
The complex computing systems employed by governments, corporations, and other institutions are frequently targeted by cyber-attacks designed for espionage and sabotage. The malicious software used in such attacks are typically custom-designed or obfuscated to avoid detection by traditional antivirus software. Our goal is to create a malware detection system that can quickly and accurately detect such otherwise difficult-to-detect malware. We pose the problem of malware detection as a multi-channel change-point detection problem, wherein the goal is to identify the point in time when a system changes from a known clean state to an infected state. We present a host-based malware detection system designed to run at the hypervisor level, monitoring hypervisor and guest operating system sensors and sequentially determining whether the host is infected. We present a case study wherein the detection system is used to detect various types of malware on an active web server under heavy computational load.
Keywords :
Internet; computational complexity; computer viruses; file servers; operating systems (computers); active Web server; antivirus software; complex computing systems; cyber-attacks; difficult-to-detect malware; espionage; guest operating system sensors; host-based malware detection system; hypervisor level; malicious software; monitoring hypervisor; multichannel change-point malware detection system; sabotage; Detectors; Feature extraction; Malware; Sensor phenomena and characterization; Software; Virtual machine monitors; behavioral detection; change detection; change-point detection; malware; multi-channel; quickest detection;
Conference_Titel :
Software Security and Reliability (SERE), 2013 IEEE 7th International Conference on
Conference_Location :
Gaithersburg, MD
Print_ISBN :
978-1-4799-0406-8
DOI :
10.1109/SERE.2013.20