Subgraph-based Metamorphic Malwares Analysis

Jonghoon Kwon, Je-Hyun Lee, Teabum Kim, Heejo Lee · 2010

Malware authors commonly used code obfuscation to evade detection mechanisms. When this technique is applied to malwares, they can change their instruction sequence and also even their signature. These malwares which have same functionality and different appearance are able to evade signature-based AV products. Thus, AV venders paid large amount of cost to analyze and classify malware for generating new signature. In this paper, we propose a new approach for analyzing metamorphic malwares. The proposed mechanism first converts malware’s API call sequences to CodeGraph through dynamic analysis. After that, we extract all subgraphs and analyze how similar two malware’s behaviors are through subgraph similarity. To validate proposed mechanism, we use 46 real-world malwares include 20 variants. In evaluation, all metamorphic malwares are classified correctly, and similar module behaviors among different malwares are also discovered.

Read the paper · More papers on PaperTik