Automatic dynamic malware analysis techniques for Linux environment

Gaurav Damri, Deepti Vidyarthi · International Conference on Computing for Sustainable Global Development · 2016

Penetration into Linux system using malware is increasing at very high rate. Primary reason for this is our perception that Linux is a secure system. Malwares are used very often to penetrate into any computer or network; malware authors are using various obfuscation techniques to impede the detection from traditional signature based Anti-virus system. Automated dynamic malware analysis systems are one of the latest weapons used by security researchers to counter them. To counter dynamic analysis, malware authors are using various evasion techniques. Challenge now lies in finding a generic and efficient technique which can detectpotentially malicious file. This article is a survey of dynamic analysis techniques proposed or implemented in the context of Linux systems. The survey classifies these approaches into five types: System-call base approach, Process Control Block based approach, ELF based approach, Linux kernel based approach and Hybrid approach. It also discusses open problems not handled by these techniques. Providing current bibliography, it may aid Linux malware researchers to identify suitable analysis technique and the way forward.

Read the paper · More papers on PaperTik