Behavioral detection of malware: from a survey towards an established taxonomy

被引:143
作者
Jacob, Gregoire [1 ,2 ]
Debar, Herve [1 ]
Filiol, Eric [2 ]
机构
[1] France Telecom R&D, Caen, France
[2] French Army Signals Acad, Virol & Cryptol Lab, Rennes, France
关键词
D O I
10.1007/s11416-008-0086-0
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 [计算机科学与技术];
摘要
Behavioral detection differs from appearance detection in that it identifies the actions performed by the malware rather than syntactic markers. Identifying these malicious actions and interpreting their final purpose is a complex reasoning process. This paper draws up a survey of the different reasoning techniques deployed among the behavioral detectors. These detectors have been classified according to a new taxonomy introduced inside the paper. Strongly inspired from the domain of program testing, this taxonomy divides the behavioral detectors into two main families: simulation-based and formal detectors. Inside these families, ramifications are then derived according to the data collection mechanisms, the data interpretation, the adopted model and its generation, and the decision support.
引用
收藏
页码:251 / 266
页数:16
相关论文
共 63 条
[1]
Anderson JP, 1980, TECH REP
[2]
[Anonymous], 2007, MALW OUTBR TREND REP
[3]
[Anonymous], 1997, SYMANTEC WHITE PAPER, VXXXIV
[4]
[Anonymous], 2001, P S REQ ENG INF SEC
[5]
[Anonymous], 1986, THESIS
[6]
[Anonymous], 2004, TECH REP
[7]
Bayer U, 2006, J COMPUT VIROL HACKI, V2, P67, DOI 10.1007/s11416-006-0012-2
[8]
Bruschi D., 2006, P INT S SEC SOFTW EN, P37
[9]
Bruschi D, 2006, LECT NOTES COMPUT SC, V4064, P129
[10]
Charlier B. L., 1995, P VIR B C