Software security through targeted diversification




















Each file is scanned and compared against a set of signatures. This ap-proach has several problems: i all possible detectable mal-ware must have a signature in the database and ii it might take a Abstract - Cited by 2 1 self - Add to MetaCart Signature-based similarity metrics are the primary mech-anism to detect malware on current systems. This ap-proach has several problems: i all possible detectable mal-ware must have a signature in the database and ii it might take a substantial amount of time between initial spread of the malware and the time anti-malware companies generate a signature to protect from the malware.

On the other hand, the malware landscape is changing: there are only few malware families alive at a certain point in time. Each family evolves along a common software update and maintenance cycle. Individual malware instances are repacked or obfuscated whenever they are detected by a large set of anti-malware products, basically resulting in an arms race between malware authors and anti-malware products.

Anti-malware products are not efficient if they follow this arms race and we show how it is possible to maximize the advantage for malware distributors. We present MalDiv, an automatic diversification mechanism that uses compiler-based transformations to generate an almost infinite amount of binaries with the same functionality but very low similar-ity, resulting in different signatures. By introducing diversity per programme instance, we illustrate how to defeat various patching methods using inlined code snippets.

Documents: Advanced Search Include Citations. Authors: Advanced Search Include Citations. Springer Google Scholar. Athanasopoulos, E. In: International Conference on Information Security, pp. Atlam, H. Springer, pp. AVTest: Malware statistics. Boyd, S. IEEE Trans. Secure Comput. Chew, M. Collberg, C. Hosseinzadeh, S. Larsen, P. IEEE Secur.



0コメント

  • 1000 / 1000