Noninvasive detection of anti-forensic malware

Mordehai Guri, Gabi Kedma, Tom Sela, Buky Carmeli, Amit Rosner, Yuval Elovici

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

7 Scopus citations

Abstract

Modern malicious programs often escape dynamic analysis, by detecting forensic instrumentation within their own runtime environment. This has become a major challenge for malware researchers and analysts. Current defensive analysis of anti-forensic malware often requires painstaking step-by-step manual inspection. Code obfuscation may further complicate proper analysis. Furthermore, current defensive countermeasures are usually effective only against anti-forensic techniques which have already been identified. In this paper we propose a new method to detect and classify anti-forensic behavior, by comparing the trace-logs of the suspect program between different environments. Unlike previous works, the presented method is essentially noninvasive (does not interfere with original program flow). We separately trace the flow of instructions (Opcode) and the flow of Input-Output operations (IO). The two dimensions (Opcode and IO) complement each other to provide reliable classification. Our method can identify split behavior of suspected programs without prior knowledge of any specific anti-forensic technique; furthermore, it relieves the malware analyst from tedious step-by-step inspection. Those features are critical in the modern Cyber arena, where rootkits and Advanced Persistent Threats (APTs) are constantly adopting new sophisticated anti-forensic techniques to deceive analysis.

Original languageEnglish
Title of host publicationProceedings of the 2013 8th International Conference on Malicious and Unwanted Software
Subtitle of host publication"The Americas", MALWARE 2013
PublisherIEEE Computer Society
Pages1-10
Number of pages10
ISBN (Print)9781479925339
DOIs
StatePublished - 1 Jan 2013
Event2013 8th International Conference on Malicious and Unwanted Software: "The Americas", MALWARE 2013 - Fajardo, PR, United States
Duration: 22 Oct 201324 Oct 2013

Publication series

NameProceedings of the 2013 8th International Conference on Malicious and Unwanted Software: "The Americas", MALWARE 2013

Conference

Conference2013 8th International Conference on Malicious and Unwanted Software: "The Americas", MALWARE 2013
Country/TerritoryUnited States
CityFajardo, PR
Period22/10/1324/10/13

Fingerprint

Dive into the research topics of 'Noninvasive detection of anti-forensic malware'. Together they form a unique fingerprint.

Cite this