Analysis of Maximum Executable Length for Detecting Text-based Malware

被引:0
|
作者
Manna, Parbati Kumar [1 ]
Ranka, Sanjay [1 ]
Chen, Shigang [1 ]
机构
[1] Univ Florida, Dept Comp & Informat Sci & Engn, Gainesville, FL 32611 USA
关键词
D O I
10.1109/ICDCS.2008.70
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
The possibility of using purely text stream (keyboard-enterable) as carrier of malware is under-researched and often underestimated. A text attack can happen at multiple levels, from code-injection attacks at the top level to host-compromising text-based machine code at the lowest level. Since a large number of protocols are text-based, at times the servers based on those protocols use ASCII filters to allow text input only. However simply applying ASCII filters to weed out the binary data is not enough from the security viewpoint since the assumption that malware are always binary is false. We show that although text is a subset of binary, binary malware detectors cannot always detect text malware. We analyze the MEL (Maximum Executable Length)-based detection schemes, and make two contributions by this analysis. First, although the concept of MEL has been used in various detection schemes earlier, we are the first to provide its underlying mathematical foundation. We show that the threshold value can be calculated from the input character frequencies and that it can be tuned to control the detection sensitivity Second, we demonstrate the effectiveness of a MEL-based text malware detector by exploiting the specific properties of text streams.
引用
收藏
页码:176 / 183
页数:8
相关论文
共 50 条
  • [31] DEAFNESS AND TEXT-BASED LITERACY
    PAUL, PV
    [J]. AMERICAN ANNALS OF THE DEAF, 1993, 138 (02) : 72 - 75
  • [32] TEXT-BASED INTELLIGENT SYSTEMS
    JACOBS, PS
    [J]. AI MAGAZINE, 1990, 11 (03) : 30 - 31
  • [33] Text-Based Recession Probabilities
    Massimo Ferrari Minesso
    Laura Lebastard
    Helena Le Mezo
    [J]. IMF Economic Review, 2023, 71 : 415 - 438
  • [34] Text-based database searching
    Lewitter, F
    [J]. TRENDS IN BIOTECHNOLOGY, 1998, : 3 - 5
  • [35] Text-Based Recession Probabilities
    Minesso, Massimo Ferrari
    Lebastard, Laura
    Le Mezo, Helena
    [J]. IMF ECONOMIC REVIEW, 2023, 71 (02) : 415 - 438
  • [36] Vowel- and Text-Based Cepstral Analysis of Chronic Hoarseness
    Moers, Cornelia
    Moebius, Bernd
    Rosanowski, Frank
    Noeth, Elmar
    Eysholdt, Ulrich
    Haderlein, Tino
    [J]. JOURNAL OF VOICE, 2012, 26 (04) : 416 - 424
  • [37] Structural analysis of binary executable headers for malware detection optimization
    Baptiste David
    Eric Filiol
    Kévin Gallienne
    [J]. Journal of Computer Virology and Hacking Techniques, 2017, 13 (2) : 87 - 93
  • [38] Climate change exposure and the takeover market: A text-based analysis
    Chindasombatcharoen, Pongsapak
    Chatjuthamard, Pattanaporn
    Jiraporn, Pornsit
    Wongsinhirun, Nopparat
    [J]. BUSINESS STRATEGY AND THE ENVIRONMENT, 2024,
  • [39] Book impact assessment: A quantitative and text-based exploratory analysis
    Piryani, Rajesh
    Gupta, Vedika
    Singh, Vivek Kumar
    Pinto, David
    [J]. JOURNAL OF INTELLIGENT & FUZZY SYSTEMS, 2018, 34 (05) : 3101 - 3110
  • [40] A Discursive and Pragmatic Analysis of WhatsApp Text-based Status Notifications
    Assaggaf, Hussein Taha
    [J]. ARAB WORLD ENGLISH JOURNAL, 2019, 10 (04) : 101 - 111