- Book Chapter
- 10.1007/978-1-4614-5523-3_7
Concluding Remarks
- Aug 14, 2012
- Heng Yin + 1 more +1
In this book, we sought to capture the intrinsic natures in malicious behaviors, in order to build more effective automatic malware analysis systems. We proposed TEMU as a dynamic binary analysis platform. Then on top of TEMU, we proposed and built a series of novel techniques for automatic malware analysis, including Renovo, Panorama, HookFinder, and MineSweeper, for detecting and analyzing various aspects of malware. Since these techniques capture intrinsic characteristics of malware, they are well suited for dealing with new malware samples and attack mechanisms. We also systematically discussed several fundamental limitations in our proposed techniques.More concretely, we pointed out that although our analysis platform is better suited for analyzing malicious code than the other conventional ones (e.g., debugger and disassembler), malware authors may still find ways to detect and evade it. Moreover, an open problem for dynamic analysis lies in its limited test coverage. Finally, as a core analysis technique, dynamic taint analysis has several limitations, including taint explosion and implicit information flow. Such discussions shed light on future directions for automatic malware analysis.KeywordsAutomated Malware AnalysisTaint AnalysisImplicit Information flowCore Analysis TechniquesMalware SamplesThese keywords were added by machine and not by the authors. This process is experimental and the keywords may be updated as the learning algorithm improves.
Read more