Sciweavers

DSN
2008
IEEE

Towards an understanding of anti-virtualization and anti-debugging behavior in modern malware

13 years 11 months ago
Towards an understanding of anti-virtualization and anti-debugging behavior in modern malware
Many threats that plague today’s networks (e.g., phishing, botnets, denial of service attacks) are enabled by a complex ecosystem of attack programs commonly called malware. To combat these threats, defenders of these networks have turned to the collection, analysis, and reverse engineering of malware as mechanisms to understand these programs, generate signatures, and facilitate cleanup of infected hosts. Recently however, new malware instances have emerged with the capability to check and often thwart these defensive activities — essentially leaving defenders blind to their activities. To combat this emerging threat, we have undertaken a robust analysis of current malware and developed a detailed taxonomy of malware defender fingerprinting methods. We demonstrate the utility of this taxonomy by using it to characterize the prevalence of these avoidance methods, to generate a novel fingerprinting method that can assist malware propagation, and to create an effective new techniq...
Xu Chen, Jonathon Andersen, Zhuoqing Morley Mao, M
Added 29 May 2010
Updated 29 May 2010
Type Conference
Year 2008
Where DSN
Authors Xu Chen, Jonathon Andersen, Zhuoqing Morley Mao, Michael Bailey, Jose Nazario
Comments (0)