Active Malware Countermeasure Approach for Mission Critical Systems

Zachary R. Thomas, Sherif Abdelwahed · 2017

This paper presents a cyber-defense system, named the Active Malware Countermeasure system, aimed at maintaining the operation of mission-critical systems by mitigating damage after compromise has occurred. This system is designed to implement techniques that will nullify the effect of malicious actions taken against mission-critical systems. Diverting identified malicious functionality away from the mission-critical system to sacrificial virtual machine(s) (VM) effectively nullifies malware. The proposed system utilizes hooking techniques to intercept malicious operations before they execute in the critical environment. The hooks are then used to facilitate diversion of malicious functions to a VM. Virtualization is used to create a safe, isolated environment where the malicious functionality can be executed without affecting the critical environment. Return values and information associated with the function execution can then be sent back to the malicious process, so its execution can proceed as normal. The maintained execution of malware in this hooked state allows the mission-critical system to continue operating as damaging functionality is diverted to the safe environment, minimizing down-time of critical operations despite compromise.

Read the paper · More papers on PaperTik