- Research Article
28
- 10.1016/j.knosys.2022.108266
Time-interval temporal patterns can beat and explain the malware
- Jan 29, 2022
- Knowledge-Based Systems
- Ido Finder + 2 more +2
Time-interval temporal patterns can beat and explain the malware
Dynamic malware analysis is essential to develop optimal intrusion detection systems. Performing this process from a virtual environment provides the advantage of containing the malware damage, so the real machine is not affected. However, it is suspected that the behavior of malware may vary when it is being executed in a virtual environment thus invalidating the results obtained when analyzing malware in these environments. In this work we dynamically analyze the behavior of nine different malware samples based on the network traffic generated by each of them. Then, this behavior was compared with ones previously registered from a physical environment. The results obtained show that malware behavior differs significantly in these two environments.
Time-interval temporal patterns can beat and explain the malware
Time-interval temporal patterns can beat and explain the malware
Scalability, fidelity and stealth in the DRAKVUF dynamic malware analysis system
Malware is one of the biggest security threats on the Internet today and deploying effective defensive solutions requires the rapid analysis of a continuously increasing number of malware samples. With the proliferation of metamorphic malware the analysis is further complicated as the efficacy of signature-based static analysis systems is greatly reduced. While dynamic malware analysis is an effective alternative, the approach faces significant challenges as the ever increasing number of samples requiring analysis places a burden on hardware resources. At the same time modern malware can both detect the monitoring environment and hide in unmonitored corners of the system.In this paper we present DRAKVUF, a novel dynamic malware analysis system designed to address these challenges by building on the latest hardware virtualization extensions and the Xen hypervisor. We present a technique for improving stealth by initiating the execution of malware samples without leaving any trace in the analysis machine. We also present novel techniques to eliminate blind-spots created by kernel-mode rootkits by extending the scope of monitoring to include kernel internal functions, and to monitor file-system accesses through the kernel's heap allocations. With extensive tests performed on recent malware samples we show that DRAKVUF achieves significant improvements in conserving hardware resources while providing a stealthy, in-depth view into the behavior of modern malware.
Read moreKinematics of Pointing Movements Made in a Virtual Versus a Physical 3-Dimensional Environment in Healthy and Stroke Subjects
Kinematics of Pointing Movements Made in a Virtual Versus a Physical 3-Dimensional Environment in Healthy and Stroke Subjects
Read moreA Hybrid Approach for Android Malware Detection and Family Classification.
With the increase in the popularity of mobile devices, malicious applications targeting Android platform have greatly increased. Malware is coded so prudently that it has become very complicated to identify. The increase in the large amount of malware every day has made the manual approaches inadequate for detecting the malware. Nowadays, a new malware is characterized by sophisticated and complex obfuscation techniques. Thus, the static malware analysis alone is not enough for detecting it. However, dynamic malware analysis is appropriate to tackle evasion techniques but incapable to investigate all the execution paths and also it is very time consuming. So, for better detection and classification of Android malware, we propose a hybrid approach which integrates the features obtained after performing static and dynamic malware analysis. This approach tackles the problem of analyzing, detecting and classifying the Android malware in a more efficient manner. In this paper, we have used a robust set of features from static and dynamic malware analysis for creating two datasets i.e. binary and multiclass (family) classification datasets. These are made publically available on GitHub and Kaggle with the aim to help researchers and anti-malware tool creators for enhancing or developing new techniques and tools for detecting and classifying Android malware. Various machine learning algorithms are employed to detect and classify malware using the features extracted after performing static and dynamic malware analysis. The experimental outcomes indicate that hybrid approach enhances the accuracy of detection and classification of Android malware as compared to the case when static and dynamic features are considered alone.
Read moreA Comparative Study of Android Malware Behavior in Different Contexts
One of the numerous ways of addressing the Android malware threat is to run malicious applications in a sandbox environment while monitoring metrics. However, dynamic malware analysis is usually concerned with a one-time execution of an application, and information about behaviour in different environments is lacking in the literature. We fill this gap with a fuzzy-like approach to the problem: by running the same malware multiple times in different environments, we gain insight on the malware behaviour and his peculiarities. To implement this approach, we leverage a client-server sandbox to run experiments, based on a common suit of actions. Scenarios are executed multiple times on a malware sample, each time with a different parameter, and results are compared to determine variation in observed behaviour. In our current experiment, variation was introduced by different levels of simulation, allowing us to compare metrics such as failure rate, data leakages, sending of SMS, and the number of HTTP and DNS requests. We find the behaviour is different for data leakages, which require no simulation to leak information, while all results for other metrics were higher when simulation was used in experiments. We expect that a fuzzing approach with others parameters will further our understanding of malware behaviour, particularly for malware bound to such parameters.
Read moreASSESSMENT OF VISUAL PERCEPTION OF WEB-BASED VIRTUAL ENVIRONMENTS SIMULATIONS OF AN URBAN CONTEXT.
The existing research literature on environmental perception is a body of work mainly based on the use of static representation of environments. However, the real world is usually experienced in a dynamic experience. Virtual environments’ technologies offer the potential to produce simulated environments that create the impression that we are in spaces other than those we actually occupy. A review of literature on environmental perception revealed two components of perception: “space-based” and “object-based” perception. An experiment was conducted to investigate visual perception obtained from a direct experience of an urban landscape and from its representations in desktop virtual environments (desktop VEs). The issues investigated were: accuracy of space-based and object-based visual perception obtained from the physical environment and from desktop virtual environment. A series of tests were administered to assess the visual perception of participants who explored the urban environment following a direct experience, and X3D-VRML models. The results indicated that participants who experienced the X3D-VRML models conducted fewer errors in space-based perception tests. There was evidence that participants in X3D-VRML perceived more objects than their counterparts in the physical environment. Similarities and differences between the physical and virtual environments were discussed suggesting the potential and limitations of desktop VEs in environmental representation. An agenda for future research work is suggested.
Read moreEfficient Dynamic Malware Analysis for Collecting HTTP Requests using Deep Learning
Malware-infected hosts have typically been detected using network-based Intrusion Detection Systems on the basis of characteristic patterns of HTTP requests collected with dynamic malware analysis. Since attackers continuously modify malicious HTTP requests to evade detection, novel HTTP requests sent from new malware samples need to be exhaustively collected in order to maintain a high detection rate. However, analyzing all new malware samples for a long period is infeasible in a limited amount of time. Therefore, we propose a system for efficiently collecting HTTP requests with dynamic malware analysis. Specifically, our system analyzes a malware sample for a short period and then determines whether the analysis should be continued or suspended. Our system identifies malware samples whose analyses should be continued on the basis of the network behavior in their short-period analyses. To make an accurate determination, we focus on the fact that malware communications resemble natural language from the viewpoint of data structure. We apply the recursive neural network, which has recently exhibited high classification performance in the field of natural language processing, to our proposed system. In the evaluation with 42,856 malware samples, our proposed system collected 94% of novel HTTP requests and reduced analysis time by 82% in comparison with the system that continues all analyses.
Read moreKnowledge Based Secure Data Streaming in Virtual Environment
The process of transferring data within any physical environment is highly vulnerable and liable to face many security issues leading to sniffing of highly confidential data by any of the prevalent cyber attacks. Presently, there are various classic data retrieving methodologies such as CASE, PIVOT and SJP within a physical environment. However, these methods are not completely fail proof against unauthorized data retrieval. This paper aims to implement the concept of Knowledge Cube generation for securely transfer data with the help of Horizontal Aggregation method in virtual environment. The concept of ‘Knowledge Cube’ is referred as a multidimensional model composing of cubes and dimensions, which can be further interpreted so as to execute complex queries during any data retrieval process in both physical and virtual environment.
Read moreAn EEG-based Evaluation for Comparing the Sense of Presence between Virtual and Physical Environments
The current study concerns the identification of possible differences in perception between the virtual and the real world in terms of the effect on brain activity. For this reason, an EEG device was used to capture participants' brain activity in different brain areas during their exposure to different virtual and real environments. The environments considered in this study portray a classroom environment with a scenario suitable for teacher training and professional development. The first aim of the experiment is to investigate if exposure to a virtual environment can affect motor, cognitive or other function of the users, and the second aim is to test if the graphics content and nature of such an environment can influence the user experience. During the study, the optimum duration of exposure in a virtual environment was also assessed by measuring the time that the brain needs to perceive and adapt to the new state. Our results, consisting of EEG data analyzed in 10 Regions of Interest (ROIs) and responses from an Igroup Presence questionnaire, indicated a significant difference in each brain area, especially in the frontal and occipital region, when a participant was exposed to a non-realistic virtual environment, compared to a realistic one, highlighting the impact of the selected virtual environment design. The results of the experiment can play an important role in defining the characteristics of optimal virtual environments for virtual reality-based training applications.
Read moreKinematics of Reaching Movements in a 2-D Virtual Environment in Adults With and Without Stroke
Virtual reality environments are increasingly being used for upper limb rehabilitation in poststroke patients. Our goal was to determine if arm reaching movements made in a 2-D video-capture virtual reality environment are similar to those made in a comparable physical environment. We compared arm and trunk kinematics for reaches made with the right, dominant arm to three targets (14 trials per target) in both environments by 16 adults with right poststroke hemiparesis and by eight healthy age-matched controls. Movement kinematics were recorded with a three-camera optoelectronic system at 100 samples/s. Reaching movements made by both control and stroke subjects were affected by viewing the targets in the video-capture 2-D virtual environment. Movements were slower, shorter, less straight, less accurate and involved smaller ranges of shoulder and elbow joint excursions for target reaches in the virtual environment compared to the physical environment in all subjects. Thus, there was a decrease in the overall movement quality for movements made in the 2-D virtual environment. This suggests that 2-D video-capture virtual reality environments should be used with caution when the goal of the rehabilitation program is to improve the quality of movement patterns of the upper limb.
Read moreVirtual reality in lighting research: Comparing physical and virtual lighting environments
In the study of lighting, as the construction of a physical test room is costly and time-consuming, researchers have been actively looking for alternative media to present physical environments. Virtual reality, photo and video are the most commonly used approaches in the lighting community, and they have all been used by researchers around the world. Most such studies have been conducted without discussing what gives the subjects a better sense of realism, presence, etc., and which type of media is closer to the ideal, the physical lighting environment. In this paper, we aim to select the optimal alternative media that can present physical lighting environments. We compare a human’s subjective feeling towards a physical lighting environment and three alternative reproduction technologies, namely, virtual reality reproduction, video reproduction and photographic reproduction. We also discuss the feasibility of using virtual reality in representing lighting environments. The selection of the most optimal media is based on the perceptual attributes of lighted space, and the findings are only related to these criteria. The main results of this study are the following: (a) The order of the overall presentation-ability of the media is physical space > virtual reality reproductions > video reproductions > photo reproductions. (b) In terms of subjective rating, virtual reality lighting environments are rated closest to the physical lighting environments, and the order of the approximate coefficient of the media is physical space (1) > VR reproductions (0.886) > video reproductions (0.752) > photo reproductions (0.679). (c) Virtual reality can present lighting attributes of open/close, diffuse/glaring, bright/dim and noisy/quiet consistent with the physical environment. (d) Human subjects are most satisfied with VR reproductions.
Read moreCoordination of reach-to-grasp in physical and haptic-free virtual environments
BackgroundVirtual reality (VR) offers unprecedented opportunity as a scientific tool to study visuomotor interactions, training, and rehabilitation applications. However, it remains unclear if haptic-free hand-object interactions in a virtual environment (VE) may differ from those performed in the physical environment (PE). We therefore sought to establish if the coordination structure between the transport and grasp components remain similar whether a reach-to-grasp movement is performed in PE and VE.MethodReach-to-grasp kinematics were examined in 13 healthy right-handed young adults. Subjects were instructed to reach-to-grasp-to-lift three differently sized rectangular objects located at three different distances from the starting position. Object size and location were matched between the two environments. Contact with the virtual objects was based on a custom collision detection algorithm. Differences between the environments were evaluated by comparing movement kinematics of the transport and grasp components.ResultsCorrelation coefficients, and the slope of the regression lines, between the reach and grasp components were similar for the two environments. Likewise, the kinematic profiles of the transport velocity and grasp aperture were strongly correlated across the two environments. A rmANOVA further identified some similarities and differences in the movement kinematics between the two environments - most prominently that the closure phase of reach-to-grasp movement was prolonged when movements were performed in VE.ConclusionsReach-to-grasp movement patterns performed in a VE showed both similarities and specific differences compared to those performed in PE. Additionally, we demonstrate a novel approach for parsing the reach-to-grasp movement into three phases- initiation, shaping, closure- based on established kinematic variables, and demonstrate that the differences in performance between the environments are attributed to the closure phase. We discuss this in the context of how collision detection parameters may modify hand-object interactions in VE. Our study shows that haptic-free VE may be a useful platform to study reach-to-grasp movements, with potential implications for haptic-free VR in neurorehabilitation.
Read moreMalware Classification Framework for Dynamic Analysis using Information Theory
Objectives: 1. To propose a framework for Malware Classification System (MCS) to analyze malware behavior dynamically using a concept of information theory and a machine learning technique. 2. To extract behavioral patterns from execution reports of malware in terms of its features and generates a data repository. 3. To select the most promising features using information theory based concepts. Methods/Statistical Analysis: Today, malware is a major concern of computer security experts. Variety and in- creasing number of malware affects millions of systems in the form of viruses, worms, Trojans etc. Many techniques have been proposed to analyze the malware to its class accurately. Some of analysis techniques analyzed malware based upon its structure, code flow, etc. without executing it (called static analysis), whereas other techniques (termed as dynamic analysis) focused to monitor the behavior of malware by executing it and comparing it with known malware behavior. Dynamic analysis has proved to be effective in malware detection as behavior is more difficult to mask while executing than its underlying code (static analysis). In this study, we propose a framework for Malware Classification System (MCS) to analyze malware behavior dynamically using a concept of information theory and a machine learning technique. The proposed framework extracts behavioral patterns from execution reports of malware in terms of its features and generates a data repository. Further, it selects the most promising features using information theory based concepts. Findings: The proposed framework detects the family of unknown malware samples after training of a classifier from malware data repository. We validated the applicability of the proposed framework by comparing with the other dynamic malware analysis technique on a real malware dataset from Virus Total. Application: The proposed framework is a Malware Classification System (MCS) to analyze malware behavior dynamically using a concept of information theory and a machine learning technique.
Read moreIntegrating Physical, Digital, and Virtual Modeling Environments in a Collaborative Design Thinking Tool
Design thinking is a creative process that requires brainstorming techniques that take place in a physical environment. However, such physical interactions are not possible in remote environments. In this paper, we propose a software tool for design thinking that bridges the gap between physical, digital, and virtual modeling environments. We describe and evaluate a virtual storyboarding application that enables remote collaborative design thinking in 3D and the conversion of these 3D models into 2D digital models. To evaluate the approach, we conducted an experiment with students and were able to derive directions for further research in this area.
Read moreIntroLib: Efficient and transparent library call introspection for malware forensics
IntroLib: Efficient and transparent library call introspection for malware forensics