• DocumentCode
    669118
  • Title

    Heuristic malware detection via basic block comparison

  • Author

    Adkins, Francis ; Jones, Lewis ; Carlisle, Michael ; Upchurch, Jason

  • Author_Institution
    Dept. of Comput. Sci., United States Air Force Acad., Colorado Springs, CO, USA
  • fYear
    2013
  • fDate
    22-24 Oct. 2013
  • Firstpage
    11
  • Lastpage
    18
  • Abstract
    Each day, malware analysts are tasked with more samples than they have the ability to analyze by hand. To produce this trend, malware authors often reuse a significant portion of their code. In this paper, we introduce a technique to statically decompose malicious software to identify shared code. This technique variably applies a sliding-window methodology to either full files or individual basic blocks to produce representative similarity ratios either between two binaries or between two functionalities within binaries, respectively. This grants the ability to apply heuristic detection via threshold similarity matching as well as full-inclusivity matching for malicious functionality. Additionally, we apply generalization techniques to minimize local assembly variants while still maintaining consistent structural matching. We also identify improvements that this technique provides over previous technologies and demonstrate its success in practical sample detection. Finally, we suggest further applications of this technique and highlight possible contributions to modern malware detection.
  • Keywords
    invasive software; program diagnostics; basic block comparison; consistent structural matching; generalization techniques; heuristic malware detection; local assembly variants; malicious functionality; malware analysts; malware authors; representative similarity ratios; sample detection; shared code identification; sliding-window methodology; static malicious software decomposition; threshold similarity matching; Assembly; Cloning; Fingerprint recognition; Indexes; Malware; Software; Software algorithms; Approved for public release; Distribution A; distribution unlimited;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Malicious and Unwanted Software: "The Americas" (MALWARE), 2013 8th International Conference on
  • Conference_Location
    Fajardo, PR
  • Print_ISBN
    978-1-4799-2534-6
  • Type

    conf

  • DOI
    10.1109/MALWARE.2013.6703680
  • Filename
    6703680