Automatic Malware Signature Generation

Karin Ask · 2006

The times when malware researchers could spend weeks analyzing a new piece of malware are long gone. Today newmalicious programs are written and distributed at such speed that it just is not possible. Virus scanners are the most common countermeasure against malware attacks and they need up-to-date signatures to successfully identify malware. This thesis describes Autosig, a program for automatic generation of malware signatures. The generation of signatures is based on the fact that most malware come in many different variants, but still share some invariant code. Using statistical data on how often certain byte combinations appear in legitimate files, Autosig extracts a substring from this invariant code to generate a signature. The signatures are tested and those that fail to pass all tests are discarded. By remembering all discarded signatures, Autosig learns which code to avoid. This technique has turned out to be successful in many of the time consuming routine cases, leaving the human analysts more time to generate working signatures for more complicated malware. It has also turned out helpful in replacing overlapping and redundant signatures, leading to a smaller signature database.

Read the paper · More papers on PaperTik