Using the presence of anti-reverse-engineering artifacts to detect malware

Chase Cotton, Ryan Van Antwerp · 2013

Malware detection is currently an arms race between malware authors and malware analysts; malware authors will develop a new way to hide their malicious intents with anti analysis techniques such as executable packing, debugger detection, virtual machine detection, and anti-disassembly while malware analysts will manually and slowly overcome these techniques over time. Typically, the more complex the anti-reverse-engineering techniques implemented, the longer it will take for a malware analyst to properly analyze a piece of malware and determine how to combat it. In this work, it was determined that overcoming these anti-reverse-engineering features is not needed, but rather the presence of these features can be used to effectively label an executable as malicious. Since it is rare for a benign (non-malicious) executable to employ anti-reverse engineering techniques, these artifacts can be used with heuristics to determine with high accuracy whether an unknown executable is malicious or not. In order to determine optimal thresholds, a support vector machine (SVM) is utilized. Using a set of known malicious and known benign samples, the SVM can be trained to create a prediction engine that can be used to classify unknown samples as either malicious or benign. Results show accuracies as high as 97% using purely static analysis techniques that do not rely on signatures.

Read the paper · More papers on PaperTik