Malware provenance: code reuse detection in malicious software at scale

Jason Upchurch, Xiaobo Zhou · 2016

Detecting code reuse in software has applications in malicious code analysis and in malware code search and retrieval, but is complicated by the lack of available source code. In this paper, we examine the methods for detecting similarity using the First Byte instruction block normalization approach proposed previously, but examine the performance and characteristics of the proposed Locality Sensitive Hashing (LSH) scheme for search and retrieval. We demonstrate that our approach allows for the construction of new super signatures without the availability of the original malware input and that signatures from constituent malware blocks can be used to construct signatures of malware variants. We compare our approach with other projects that propose a similar method and show the effectiveness of our approach with regards to a known malware dataset. Experimental results show that our approach is advantageous in detection accuracy and comparison time.

Read the paper · More papers on PaperTik