- Title
- Mining malware secrets
- Creator
- Lakhotia, Arun; Black, Paul
- Date
- 2017
- Type
- Text; Conference proceedings; Conference paper
- Identifier
- http://researchonline.federation.edu.au/vital/access/HandleResolver/1959.17/167745
- Identifier
- vital:13693
- Identifier
-
https://doi.org/10.1109/MALWARE.2017.8323952
- Identifier
- ISBN:978-1-5386-1433-4
- Abstract
- Malware analysts, besides being tasked to create signatures, are also called upon to generate indicators of compromise, to disrupt botnets, to attribute an attack to an actor, and to understand the adversary's intent. This requires extracting from malware a variety of secrets, aka threat intelligence. After studying a few samples from a malware family and locating where its secrets are embedded, analysts create rules that may be used to automatically extract threat intelligence from malware variants in the future. Rules to extract secrets from malware are today written as regular expressions over bytecodes, such as using Yara. These rules are easily invalidated by polymorphic variants or evolutionary versions. Keeping the rules updated is a maintenance challenge for malware analysts. Instead of using bytecode, we present the use of code semantics to create rules to extract malware secrets. The semantics of code captures the effect of instructions on the registers and memory. Rules written using the structure of the symbolic content of registers and memory, instead of bytecode, are more resilient to code transformation and evolutionary changes, and are thus less brittle and easier to maintain.
- Publisher
- IEEE
- Relation
- 2017 12th International Conference On Malicious and Unwanted Software, MALWARE 2017; Fajardo, United States; 11th-14th October 2017 Vol. 2018, p. 11-18
- Rights
- Copyright © 2017 by IEEE. Copyright and Reprint Permission: Abstracting is permitted with credit to the source. Libraries are permitted to photocopy beyond the limit of U.S. copyright law for private use of patrons those articles in this volume that carry a code at the bottom of the first page, provided the per-copy fee indicated in the code is paid through Copyright Clearance Center, 222 Rosewood Drive, Danvers, MA 01923. For other copying, reprint or republication permission, write to IEEE Copyrights Manager, IEEE Operations Center, 445 Hoes Lane, Piscataway, NJ 08854. All rights reserved.
- Rights
- This metadata is freely available under a CCO license
- Subject
- Computer crime; Viruses; Malware classification
- Reviewed
- Hits: 483
- Visitors: 449
- Downloads: 1
Thumbnail | File | Description | Size | Format |
---|