Synthesizing Near-Optimal Malware Specifications From Suspicious Behaviors

Date Added: Apr 2010
Format: PDF

Fueled by an emerging underground economy, malware authors are exploiting vulnerabilities at an alarming rate. To make matters worse, obfuscation tools are commonly available, and much of the malware is open source, leading to a huge number of variants. Behavior-based detection techniques are a promising solution to this growing problem. However, these detectors require precise specifications of malicious behavior that do not result in an excessive number of false alarms. In this paper, the authors present an automatic technique for extracting optimally discriminative specifications, which uniquely identify a class of programs.