FindEvasion: An effective environment-sensitive malware detection system for the cloud

Xiaoqi Jia, Guangzhe Zhou, Qingjia Huang*, Weijuan Zhang, Donghai Tian

*此作品的通讯作者

科研成果: 书/报告/会议事项章节会议稿件同行评审

6 引用 (Scopus)

摘要

In recent years, environment-sensitive malwares are growing rapidly and they pose significant threat to cloud platforms. They may maliciously occupy the computing resources and steal the tenants’ private data. The environment-sensitive malware can identify the operating environment and perform corresponding malicious behaviors in different environments. This greatly increased the difficulty of detection. At present, the research on automatic detection of environment-sensitive malwares is still rare, but it has attracted more and more attention. In this paper, we present FindEvasion, a cloud-oriented system for detecting environment-sensitive malware. Our FindEvasion system makes full use of the virtualization technology to transparently extract the suspicious programs from the tenants’ Virtual Machine (VM), and analyzes them on our multiple operating environments. We introduce a novel algorithm, named Mulitiple Behavioral Sequences Similarity (MBSS), to compare a suspicious program’s behavioral profiles observed in multiple analysis environments, and determine whether the suspicious program is an environment-sensitive malware or not. The experiment results show that our approach produces better detection results when compared with previous methods.

源语言英语
主期刊名Digital Forensics and Cyber Crime - 9th International Conference, ICDF2C 2017, Proceedings
编辑Martin Schmiedecker, Petr Matousek
出版商Springer Verlag
3-17
页数15
ISBN(印刷版)9783319736969
DOI
出版状态已出版 - 2018
活动9th International Conference on Digital Forensics and Cyber Crime, ICDF2C 2017 - Prague, 捷克共和国
期限: 9 10月 201711 10月 2017

出版系列

姓名Lecture Notes of the Institute for Computer Sciences, Social-Informatics and Telecommunications Engineering, LNICST
216
ISSN(印刷版)1867-8211

会议

会议9th International Conference on Digital Forensics and Cyber Crime, ICDF2C 2017
国家/地区捷克共和国
Prague
时期9/10/1711/10/17

指纹

探究 'FindEvasion: An effective environment-sensitive malware detection system for the cloud' 的科研主题。它们共同构成独一无二的指纹。

引用此