• Home
  • Search
  • Identifying Dormant Functionality in Malware Programs
  • Cite Icon111
  • https://doi.org/10.1109/sp.2010.12Copy DOI Icon

Identifying Dormant Functionality in Malware Programs

  • Jan 1, 2010
  • Paolo Milani Comparetti +5 more
Show More
  • Abstract
  • Literature Map
  • References
  • Citations
  • Similar Papers
Abstract

To handle the growing flood of malware, security vendors and analysts rely on tools that automatically identify and analyze malicious code. Current systems for automated malware analysis typically follow a dynamic approach, executing an unknown program in a controlled environment (sandbox) and recording its runtime behavior. Since dynamic analysis platforms directly run malicious code, they are resilient to popular malware defense techniques such as packing and code obfuscation. Unfortunately, in many cases, only a small subset of all possible malicious behaviors is observed within the short time frame that a malware sample is executed. To mitigate this issue, previous work introduced techniques such as multipath or forced execution to increase the coverage of dynamic malware analysis. Unfortunately, using these techniques is potentially expensive, as the number of paths that require analysis can grow exponentially. In this paper, we propose REANIMATOR, a novel solution to determine the capabilities (malicious functionality) of malware programs. Our solution is based on the insight that we can leverage behavior observed while dynamically executing a specific malware sample to identify similar functionality in other programs. More precisely, when we observe malicious actions during dynamic analysis, we automatically extract and model the parts of the malware binary that are responsible for this behavior. We then leverage these models to check whether similar code is present in other samples. This allows us to statically identify dormant functionality (functionality that is not observed during dynamic analysis) in malicious programs. We evaluate our approach on thousands of realworld malware samples, and we show that our system is successful in identifying additional, malicious functionality. As a result, our approach can significantly improve the coverage of malware analysis results.

Similar Papers
  • Book Chapter

Concluding Remarks

  • Aug 14, 2012
  • Heng Yin +1
  • Book Chapter
  • Citations2

Formal Framework for Reasoning About the Precision of Dynamic Analysis

  • Jan 01, 2020
  • Mila Dalla Preda +2
  • Conference Article
  • Citations182

Scalability, fidelity and stealth in the DRAKVUF dynamic malware analysis system

  • Dec 08, 2014
  • Tamas K Lengyel +5
  • Dissertation

Data flow and heap analysis with application to privilege escalation vulnerability scanning and software theft detection

  • Jan 01, 2013
  • Ping-Fai Chan
  • Conference Article

A machine learning approach for detecting and categorizing evasion sources in Android malware

  • Sep 01, 2021
  • Hasan Deeb +3
  • Conference Article
  • Citations14

Extracting Sent Message Formats from Executables Using Backward Slicing

  • Sep 01, 2013
  • Min Liu +3
  • Book Chapter
  • Citations16

Replacement Attacks: Automatically Impeding Behavior-Based Malware Specifications

  • Jan 01, 2015
  • Jiang Ming +5
  • PDF
  • Research Article
  • Citations10

Security implications of running windows software on a Linux system using Wine: a malware analysis study

  • Apr 26, 2018
  • Journal of Computer Virology and Hacking Techniques
  • Rory Duncan +1
  • Conference Article
  • Citations4

Efficient Method for Analyzing Malicious Websites by Using Multi-Environment Analysis System

  • Aug 01, 2017
  • Masanori Hirotomo +5
  • Conference Article
  • Citations1

Remote Injected Code Behavior Analysis using Code Refactor

  • Jun 24, 2022
  • Qian Zhang +3
  • Research Article
  • Citations4

Efficient Dynamic Malware Analysis for Collecting HTTP Requests using Deep Learning

  • Apr 01, 2019
  • IEICE Transactions on Information and Systems
  • Toshiki Shibahara +4
  • Conference Article
  • Citations6

APPLICATIONS OF MACHINE LEARNING IN MALWARE DETECTION

  • Apr 11, 2019
  • eLearning and Software for Education
  • Janalexandru Vaduva +3
  • Research Article
  • Citations23

Alterdroid: Differential Fault Analysis of Obfuscated Smartphone Malware

  • Jan 01, 2015
  • IEEE Transactions on Mobile Computing
  • Guillermo Suarez-Tangil +3
  • Research Article

A COMPREHENSIVE REVIEW ON MALWARE DETECTION TECHNIQUES

  • Jan 17, 2025
  • International Journal on Science and Technology
  • Unnimaya M U -
  • Research Article
  • Citations18

IntroLib: Efficient and transparent library call introspection for malware forensics

  • Aug 01, 2012
  • Digital Investigation
  • Zhui Deng +3
Cactus Communications logo

Copyright 2026 Cactus Communications. All rights reserved.