Subroutine based detection of APT malware

被引:14
|
作者
Sexton J. [1 ]
Storlie C. [1 ]
Anderson B. [1 ]
机构
[1] Los Alamos National Laboratory, Los Alamos, NM
关键词
APT; Malware detection; Static analysis; Subroutine similarity;
D O I
10.1007/s11416-015-0258-7
中图分类号
学科分类号
摘要
Statistical detection of mass malware has been shown to be highly successful. However, this type of malware is less interesting to cyber security officers of larger organizations, who are more concerned with detecting malware indicative of a targeted attack. Here we investigate the potential of statistically based approaches to detect such malware using a malware family associated with a large number of targeted network intrusions. Our approach is complementary to the bulk of statistical based malware classifiers, which are typically based on measures of overall similarity between executable files. One problem with this approach is that a malicious executable that shares some, but limited, functionality with known malware is likely to be misclassified as benign. Here a new approach to malware classification is introduced that classifies programs based on their similarity with known malware subroutines. It is illustrated that malware and benign programs can share a substantial amount of code, implying that classification should be based on malicious subroutines that occur infrequently, or not at all in benign programs. Various approaches to accomplishing this task are investigated, and a particularly simple approach appears the most effective. This approach simply computes the fraction of subroutines of a program that are similar to malware subroutines whose likes have not been found in a larger benign set. If this fraction exceeds around 1.5 %, the corresponding program can be classified as malicious at a 1 in 1000 false alarm rate. It is further shown that combining a local and overall similarity based approach can lead to considerably better prediction due to the relatively low correlation of their predictions. © 2015, Springer-Verlag France (Outside the USA).
引用
收藏
页码:225 / 233
页数:8
相关论文
共 50 条
  • [1] New approach for APT malware detection on the workstation based on process profile
    Cho Do Xuan
    Huong, D. T.
    Duc Duong
    JOURNAL OF INTELLIGENT & FUZZY SYSTEMS, 2022, 43 (04) : 4815 - 4834
  • [2] HTTP-Based APT Malware Infection Detection Using URL Correlation Analysis
    Niu, Wei-Na
    Xie, Jiao
    Zhang, Xiao-Song
    Wang, Chong
    Li, Xin-Qiang
    Chen, Rui-Dong
    Liu, Xiao-Lei
    SECURITY AND COMMUNICATION NETWORKS, 2021, 2021 (2021)
  • [3] A new approach for APT malware detection based on deep graph network for endpoint systems
    Cho Do Xuan
    DT Huong
    Applied Intelligence, 2022, 52 : 14005 - 14024
  • [4] A novel intelligent cognitive computing-based APT malware detection for Endpoint systems
    Do Xuan, Cho
    Huong, D. T.
    Nguyen, Toan
    JOURNAL OF INTELLIGENT & FUZZY SYSTEMS, 2022, 43 (03) : 3527 - 3547
  • [5] A new approach for APT malware detection based on deep graph network for endpoint systems
    Cho Do Xuan
    Huong, D. T.
    APPLIED INTELLIGENCE, 2022, 52 (12) : 14005 - 14024
  • [6] APT Attribution for Malware Based on Time Series Shapelets
    Wang, Qinqin
    Yan, Hanbing
    Zhao, Chang
    Mei, Rui
    Han, Zhihui
    Zhou, Yu
    2022 IEEE INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS, TRUSTCOM, 2022, : 769 - 777
  • [7] Bon-APT: Detection, attribution, and explainability of APT malware using temporal segmentation of API calls
    Shenderovitz, Gil
    Nissim, Nir
    COMPUTERS & SECURITY, 2024, 142
  • [8] Identifying APT Malware Domain Based on Mobile DNS Logging
    Niu, Weina
    Zhang, Xiaosong
    Yang, Guowu
    Zhu, Jianan
    Ren, Zhongwei
    MATHEMATICAL PROBLEMS IN ENGINEERING, 2017, 2017
  • [9] Malware Triage Based on Static Features and Public APT Reports
    Laurenza, Giuseppe
    Aniello, Leonardo
    Lazzeretti, Riccardo
    Baldoni, Roberto
    CYBER SECURITY CRYPTOGRAPHY AND MACHINE LEARNING (CSCML 2017), 2017, 10332 : 288 - 305
  • [10] Detecting APT Malware Infections Based on Malicious DNS and Traffic Analysis
    Zhao, Guodong
    Xu, Ke
    Xu, Lei
    Wu, Bo
    IEEE ACCESS, 2015, 3 : 1132 - 1142