Behavioral analysis of malicious code through network traffic and system call monitoring
Andre Ricardo Abed Gregio, Dario Simões Fernandes Filho, Vitor Monte Afonso, Rafael Santos, Mário Jino, Paulo Lício de Geus · Proceedings of SPIE, the International Society for Optical Engineering/Proceedings of SPIE · 2011
Malicious code (malware) that spreads through the Internet-such as viruses, worms and trojans-is a major threat to information security nowadays and a profitable business for criminals. There are several approaches to analyze malware by monitoring its actions while it is running in a controlled environment, which helps to identify malicious behaviors. In this article we propose a tool to analyze malware behavior in a non-intrusive and effective way, extending the analysis possibilities to cover malware samples that bypass current approaches and also fixes some issues with these approaches.