FindEvasion: An effective environment-sensitive malware detection system for the cloud

Xiaoqi Jia, Guangzhe Zhou, Qingjia Huang*, Weijuan Zhang, Donghai Tian

*Corresponding author for this work

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

6 Citations (Scopus)

Abstract

In recent years, environment-sensitive malwares are growing rapidly and they pose significant threat to cloud platforms. They may maliciously occupy the computing resources and steal the tenants’ private data. The environment-sensitive malware can identify the operating environment and perform corresponding malicious behaviors in different environments. This greatly increased the difficulty of detection. At present, the research on automatic detection of environment-sensitive malwares is still rare, but it has attracted more and more attention. In this paper, we present FindEvasion, a cloud-oriented system for detecting environment-sensitive malware. Our FindEvasion system makes full use of the virtualization technology to transparently extract the suspicious programs from the tenants’ Virtual Machine (VM), and analyzes them on our multiple operating environments. We introduce a novel algorithm, named Mulitiple Behavioral Sequences Similarity (MBSS), to compare a suspicious program’s behavioral profiles observed in multiple analysis environments, and determine whether the suspicious program is an environment-sensitive malware or not. The experiment results show that our approach produces better detection results when compared with previous methods.

Original languageEnglish
Title of host publicationDigital Forensics and Cyber Crime - 9th International Conference, ICDF2C 2017, Proceedings
EditorsMartin Schmiedecker, Petr Matousek
PublisherSpringer Verlag
Pages3-17
Number of pages15
ISBN (Print)9783319736969
DOIs
Publication statusPublished - 2018
Event9th International Conference on Digital Forensics and Cyber Crime, ICDF2C 2017 - Prague, Czech Republic
Duration: 9 Oct 201711 Oct 2017

Publication series

NameLecture Notes of the Institute for Computer Sciences, Social-Informatics and Telecommunications Engineering, LNICST
Volume216
ISSN (Print)1867-8211

Conference

Conference9th International Conference on Digital Forensics and Cyber Crime, ICDF2C 2017
Country/TerritoryCzech Republic
CityPrague
Period9/10/1711/10/17

Keywords

  • Cloud security
  • Environment-sensitive malware
  • MBSS
  • Multiple operating environments
  • Transparent extraction

Fingerprint

Dive into the research topics of 'FindEvasion: An effective environment-sensitive malware detection system for the cloud'. Together they form a unique fingerprint.

Cite this