Static Analysis of Executables to Detect Malicious Patterns

Mihai Christodorescu, Somesh Jha · 2006

Abstract Malicious code detection is a crucial component of any defense mechanism. In this paper, we present a uniqueviewpoint on malicious code detection. We regard malicious code detection as an obfuscation-deobfuscation game between malicious code writers and researchers working on malicious code detection. Malicious code writers attemptto obfuscate the malicious code to subvert the malicious code detectors, such as anti-virus software. We tested the resilience of three commercial virus scanners against code obfuscation attacks. The results were surprising: the threecommercial virus scanners could be subverted by very simple obfuscation transformations! We present an architecture for detecting malicious patterns in executables that is resilient to common obfuscation transformations. Experimentalresults demonstrate the efficacy of our prototype tool, SAFE (a static analyzer for executables). 1 Introduction In the interconnected world of computers, malicious code has become an omnipresent and dangerous threat. Maliciouscode can infiltrate hosts using a variety of methods such as attacks against known software flaws, hidden functionality in regular programs, and social engineering. Given the devastating effect malicious code has on our cyber infrastruc-ture, identifying malicious programs is an important goal. Detecting the presence of malicious code on a given host is a crucial component of any defense mechanism. Malicious code is usually classified [28] according to its propagation method and goal into the following categories:*

Read the paper · More papers on PaperTik