Evasive malware detection using groups of processes

7Citations
Citations of this article
11Readers
Mendeley users who have this article in their library.

This article is free to access.

Abstract

Fueled by a recent boost in revenue, cybercriminals are developing increasingly sophisticated and advanced malicious applications.This new generation of malware is able to avoid most of the existing detection methods. Even behavioral detection solutions are no longer immune to evasion, mostly because existing solutions focus on the actions or characteristics of a single process. We propose shifting the focus from malware as a single component to a more accurate perspective of malware as multi-component systems. We propose a dynamic behavioral detection solution that identifies groups of related processes, analyzes the actions performed by processes in these groups using behavioral heuristics and evaluates their behavior such that even evasive, multiprocess malware can be detected. Using the information provided by groups of processes, once a malware has been detected, a more comprehensive system cleanup can be performed, to ensure that all traces of an attack have been removed and the system is no longer at risk.

Cite

CITATION STYLE

APA

Hăjmăşan, G., Mondoc, A., Portase, R., & Creţ, O. (2017). Evasive malware detection using groups of processes. In IFIP Advances in Information and Communication Technology (Vol. 502, pp. 32–45). Springer New York LLC. https://doi.org/10.1007/978-3-319-58469-0_3

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free