2013•Security and Communication NetworksRequires access

A dynamic malware analyzer against virtual machine aware malicious software

Abdurrahman Pektaş, Tankut Acarman

Open publisher page 28 citations

Abstract

ABSTRACT Nowadays, cyber‐world is being enriched by a large variety of digital information technology‐based services. An increasing rate of remote and mobile usage leads to a remarkable dependency on information security. Analysis and detection of malicious software or so‐called malware is a challenging task due to the introduction of advanced obfuscation techniques by malware authors. In this study, we mainly concentrate on anti‐virtual machine evasion techniques to provide secure and reproducible environments for malware analysis and its implementation issues. Malwares are identified on the basis of their behaviors by taking precautions related to the anti‐virtual machine detection techniques. The dynamic malware analyzer tool is deployed to execute anti‐virtual machine‐aware malware samples in VMware environment. Dynamic malware analyzer monitors system resources such as connections, processes, windows registry, and file operations. Success ratio of detection is tested by using public malware sets with an accuracy of 92%. The effectiveness and success of the behavior‐based malware analyzer tool is exploited and current state of the art of malware detection schemes is presented. Copyright © 2013 John Wiley & Sons, Ltd.

About this research paper

What this paper is about

ABSTRACT Nowadays, cyber‐world is being enriched by a large variety of digital information technology‐based services. An increasing rate of remote and mobile usage leads to a remarkable dependency on information security. Analysis and detection of malicious software or so‐called malware is a challenging task due to the introduction of advanced obfuscation techniques by malware authors. In this study, we mainly concentrate on anti‐virtual machine evasion techniques to provide secure and reproducible environments for malware analysis and its implementation issues. Malwares are identified on the basis of their behaviors by taking precautions related to the anti‐virtual machine detection techniques. The dynamic malware analyzer tool is deployed to execute anti‐virtual machine‐aware malware samples in VMware environment. Dynamic malware analyzer monitors system resources such as connections, processes, windows registry, and file operations. Success ratio of detection is tested by using public malware sets with an accuracy of 92%. The effectiveness and success of the behavior‐based malware analyzer tool is exploited and current state of the art of malware detection schemes is presented. Copyright © 2013 John Wiley & Sons, Ltd.

Why it matters

OpenAlex reports 28 citations for this work. Citation counts describe recorded attention and do not establish research quality.

Key contribution

A contribution statement is not available in the OpenAlex record.

Method / approach

Method details are not available in the OpenAlex metadata.

Main findings

Findings are not separately available in the OpenAlex metadata.

Limitations

Limitations are not available in the OpenAlex metadata.

Applications

Application details are not available in the OpenAlex metadata.

Available abstract

ABSTRACT Nowadays, cyber‐world is being enriched by a large variety of digital information technology‐based services. An increasing rate of remote and mobile usage leads to a remarkable dependency on information security. Analysis and detection of malicious software or so‐called malware is a challenging task due to the introduction of advanced obfuscation techniques by malware authors. In this study, we mainly concentrate on anti‐virtual machine evasion techniques to provide secure and reproducible environments for malware analysis and its implementation issues. Malwares are identified on the basis of their behaviors by taking precautions related to the anti‐virtual machine detection techniques. The dynamic malware analyzer tool is deployed to execute anti‐virtual machine‐aware malware samples in VMware environment. Dynamic malware analyzer monitors system resources such as connections, processes, windows registry, and file operations. Success ratio of detection is tested by using public malware sets with an accuracy of 92%. The effectiveness and success of the behavior‐based malware analyzer tool is exploited and current state of the art of malware detection schemes is presented. Copyright © 2013 John Wiley & Sons, Ltd.

Key concepts: Computer science, Malware, Software, Spectrum analyzer, Computer security, Virtual machine, Operating system, Telecommunications

Related papers

Back to paper searchBrowse research topicsOriginal source
A dynamic malware analyzer against virtual machine aware malicious software — Research Paper | ScholarLens