DocumentCode
652863
Title
AUTOVAC: Automatically Extracting System Resource Constraints and Generating Vaccines for Malware Immunization
Author
Zhaoyan Xu ; Jialong Zhang ; Guofei Gu ; Zhiqiang Lin
Author_Institution
SUCCESS Lab., Texas A&M Univ., College Station, TX, USA
fYear
2013
fDate
8-11 July 2013
Firstpage
112
Lastpage
123
Abstract
Malware often contains many system-resource-sensitive condition checks to avoid any duplicate infection, make sure to obtain required resources, or try to infect only targeted computers, etc. If we are able to extract the system resource constraints from malware code, and manipulate the environment state as vaccines, we would then be able to immunize a computer from infections. Towards this end, this paper provides the first systematic study and presents a prototype system, AUTOVAC, for automatically extracting the system resource constraints from malware code and generating vaccines based on the system resource conditions. Specifically, through monitoring the data propagation from system-resource-related system calls, AUTOVAC automatically identifies the environment related state of a computer. Through analyzing the environment state, AUTOVAC automatically generates vaccines. Such vaccines can be then injected into other computers, thereby being immune from future infections from the same malware or its polymorphic variants. We have evaluated AUTOVAC on a large set of real-world malware samples and successfully extracted working vaccines for many families including high-profile Conficker, Sality and Zeus. We believe AUTOVAC represents an appealing technique to complement existing malware defenses.
Keywords
invasive software; AUTOVAC prototype system; Conficker; Sality; Zeus; data propagation monitoring; duplicate infection; environment state; malware code; malware defenses; malware immunization; polymorphic variants; system resource conditions; system resource constraints; system-resource-related system calls; system-resource-sensitive condition checks; vaccines; Algorithm design and analysis; Computers; Context; Immune system; Malware; Software; Vaccines; Dynamic malware analysis; environment constraint; vaccine.;
fLanguage
English
Publisher
ieee
Conference_Titel
Distributed Computing Systems (ICDCS), 2013 IEEE 33rd International Conference on
Conference_Location
Philadelphia, PA
ISSN
1063-6927
Type
conf
DOI
10.1109/ICDCS.2013.69
Filename
6681581
Link To Document