Abstract
One of the goals of malware analysis is to figure out the intention of an attacker, namely high-level mechanism. Since malicious activities are typically performed by combining multiple APIs, to identify the malicious intention, it is needed to inspect the series of APIs to analyze its semantics. In traditional malware analysis, this task generally relies on manual efforts of experts. There is no methodology for associating multiple APIs and identifying the malicious intention in an automated manner. In this paper, we propose a virtual machine introspection-based method for automatically identifying high-level mechanisms. We developed Spaniel, a prototype system, which uses taint analysis to track malicious processing that derives from the data read from a specified file and collects the traces of malicious activities. For evaluation, we used adversary behavior models defined in ATT&CK and Spaniel identified key indicators that cover 26% of those models.
Author supplied keywords
Cite
CITATION STYLE
Yonamine, S., Kadobayashi, Y., Miyamoto, D., & Taenaka, Y. (2019). Towards Automated Characterization of Malware’s High-level Mechanism using Virtual Machine Introspection. In International Conference on Information Systems Security and Privacy (pp. 471–478). Science and Technology Publications, Lda. https://doi.org/10.5220/0007405504710478
Register to see more suggestions
Mendeley helps you to discover research relevant for your work.