Low-level Features for Multinomial Malware Classification
Sergii Banin 10.05.2017
Sergii Banin, COINS Finse Winter School, 10.05.2017 1
Low-level Features for Multinomial Malware Classification Sergii - - PowerPoint PPT Presentation
Low-level Features for Multinomial Malware Classification Sergii Banin 10.05.2017 Sergii Banin, COINS Finse Winter School, 1 10.05.2017 Agenda Introduction (problem description). Previous research. Malware classification
Sergii Banin 10.05.2017
Sergii Banin, COINS Finse Winter School, 10.05.2017 1
Sergii Banin, COINS Finse Winter School, 10.05.2017 2
by malware.
Sergii Banin, COINS Finse Winter School, 10.05.2017 3
Sergii Banin, COINS Finse Winter School, 10.05.2017 4
instrumentation tool Intel Pin.
96-grams.
Sergii Banin, COINS Finse Winter School, 10.05.2017 5
Sergii Banin 10.05.2017
Sergii Banin, COINS Finse Winter School, 10.05.2017 6
Sergii Banin, COINS Finse Winter School, 10.05.2017 7
[https://cme.mitre.org/about/]
functionality, variation of a certain sample, etc.
[http://security.di.unimi.it/~roberto/teaching/vigorelli/0607/malware/material/caro.pdf, https://zeltser.com/malware-naming-approaches/, https://www.microsoft.com/en- us/security/portal/mmpc/shared/malwarenaming.aspx ]
Sergii Banin, COINS Finse Winter School, 10.05.2017 8
Sergii Banin, COINS Finse Winter School, 10.05.2017 9
With classification we can:
Sergii Banin, COINS Finse Winter School, 10.05.2017 10
while asking for ransom to be paid.
performed on the victim system.
computer.
Sergii Banin, COINS Finse Winter School, 10.05.2017 11
functionality.
Center) can run from PDF, MSI or EXE file. Create files in system directories, change registry entries related to software protection, capture screenshots, steal cookies, download and install new executables etc.
Sergii Banin, COINS Finse Winter School, 10.05.2017 12
Reasons for separating malware by families and types.
counter-measures.
actions for restoring and cleaning the system.
Sergii Banin, COINS Finse Winter School, 10.05.2017 13
virus classification strategy:
kernel process.
polymorphism, stealth.
Sergii Banin, COINS Finse Winter School, 10.05.2017 14
Sergii Banin, COINS Finse Winter School, 10.05.2017 SANS 15
malware classification:
filesystem/registry/network activity. [Malware Analysis and Classification: A Survey Ekta Gandotra , Divya Bansal ,
Sanjeev Sofat] Sergii Banin, COINS Finse Winter School, 10.05.2017 16
(Based on SANS taxonomy)
(ongoing research)
and CPU.
Sergii Banin, COINS Finse Winter School, 10.05.2017 17
taxonomies.
new classification methods.
Sergii Banin, COINS Finse Winter School, 10.05.2017 18
Sergii Banin, COINS Finse Winter School, 10.05.2017 19