Skip to main navigation Skip to search Skip to main content

Semantically non-preserving transformations for antivirus evaluation

  • Erkan Ersan
  • , Lior Malka
  • , Bruce M. Kapron

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

1 Scopus citations

Abstract

We relax the notion of malware obfuscation to include semantically non-preserving transformations. Unlike traditional obfuscation techniques, these transformation may not preserve original code behaviour. Using web-based malware we focus on transformations which modify abstract syntax trees. While such transformations yield syntactically valid programs, they may yield dysfunctional samples, so that it is not clear that this is a practical approach to producing detection-evading malware. However, by implementing an automated system that efficiently filters dysfunctional samples on a virtual cloud architecture, we show that such transformations are in fact practical. Using two simple transformations, we evaluated four antivirus products and were able to create many samples that evade detection, demonstrating that semantic-preserving obfuscation is not the only effective way to mutate malware.

Original languageEnglish
Title of host publicationFoundations and Practice of Security - 9th International Symposium, FPS 2016, Revised Selected Papers
EditorsJoaquin Garcia-Alfaro, Frederic Cuppens, Nora Cuppens-Boulahia, Lingyu Wang, Nadia Tawbi
PublisherSpringer Verlag
Pages273-281
Number of pages9
ISBN (Print)9783319519654
DOIs
StatePublished - 1 Jan 2017
Externally publishedYes
Event9th International Symposium on Foundations and Practice of Security, FPS 2016 - Quebec, Canada
Duration: 24 Oct 201626 Oct 2016

Publication series

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume10128 LNCS
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

Conference9th International Symposium on Foundations and Practice of Security, FPS 2016
Country/TerritoryCanada
CityQuebec
Period24/10/1626/10/16

ASJC Scopus subject areas

  • Theoretical Computer Science
  • General Computer Science

Fingerprint

Dive into the research topics of 'Semantically non-preserving transformations for antivirus evaluation'. Together they form a unique fingerprint.

Cite this