SigMal: A Static Signal Processing Based Malware Triage Dhilung - - PowerPoint PPT Presentation

sigmal a static signal processing based malware triage
SMART_READER_LITE
LIVE PREVIEW

SigMal: A Static Signal Processing Based Malware Triage Dhilung - - PowerPoint PPT Presentation

SigMal: A Static Signal Processing Based Malware Triage Dhilung Kirat Lakshmanan Nataraj Giovanni Vigna B.S Manjunath Ezeanaka Kingsley CISC850 Cyber Analytics CISC850 Cyber Analytics Abstract Sigmal as a malware detection framework -


slide-1
SLIDE 1

SigMal: A Static Signal Processing Based Malware Triage

Dhilung Kirat Lakshmanan Nataraj Giovanni Vigna B.S Manjunath

Ezeanaka Kingsley

CISC850 Cyber Analytics

slide-2
SLIDE 2

CISC850 Cyber Analytics

  • Sigmal as a malware detection framework
  • Results of testing Sigmal on samples

Abstract

slide-3
SLIDE 3
  • Static, dynamic and statistical analyses
  • Malwares variants
  • N-gram feature extraction

Introduction

CISC850 Cyber Analytics

slide-4
SLIDE 4

CISC850 Cyber Analytics

slide-5
SLIDE 5

CISC850 Cyber Analytics

Signal processing based features

  • Feature extraction, Feature computation

Section aware feature extraction

slide-6
SLIDE 6

CISC850 Cyber Analytics

slide-7
SLIDE 7

Comparison

  • N-gram based detection
  • PE structure based detection
  • Control flow graph-based detection

CISC850 Cyber Analytics

slide-8
SLIDE 8
  • Benign, Malicious and real world datasets collected

CISC850 Cyber Analytics

slide-9
SLIDE 9

CISC850 Cyber Analytics

Fig 5: Feature robustness against noise.

Evaluation

slide-10
SLIDE 10

CISC850 Cyber Analytics

  • Fig. 6 : Nearest neighbor distribution for a 100 thousand samples
slide-11
SLIDE 11

CISC850 Cyber Analytics

  • Fig. 7 : Comparison of malware detection algorithms
slide-12
SLIDE 12

CISC850 Cyber Analytics

  • Fig. 8 : Query performance comparison.
slide-13
SLIDE 13

Real world experiments

CISC850 Cyber Analytics

slide-14
SLIDE 14

CISC850 Cyber Analytics

  • Fig. 10: Precision and recall of the Sigmal detection on the real world samples.

Results:

slide-15
SLIDE 15

CISC850 Cyber Analytics

slide-16
SLIDE 16

CISC850 Cyber Analytics

Limitations and Related Work:

  • Signal Processing
  • Static malware similarity
slide-17
SLIDE 17

CISC850 Cyber Analytics

Conclusion:

  • Sigmal detection framework.
  • Heuristics based features
  • High precision capability.