Tutorial: an Overview of Malware Detection and Evasion Techniques

Biondi, Fabrizio;Given-Wilson, Thomas;Legay, Axel;Puodzius, Cassius;Quilbeuf, Jean
(2018) ISoLA (5.November.2018)

Files

No attached file found for this publication.

Details

Authors
  • Biondi, Fabrizio
    Author
  • Given-Wilson, Thomasorcid-logo
    Author
  • Legay, AxelUCLouvain
    Author
  • Puodzius, Cassius
    Author
  • Quilbeuf, Jean
    Author
Abstract
This tutorial presents and motivates various malware detection tools and illustrates their usage on a clear example. We demonstrate how statically-extracted syntactic signatures can be used for quickly detecting simple variants of malware. Since such signatures can easily be obfuscated, we also present dynamically-extracted behavioral signatures which are obtained by running the malware in an isolated environment known as a sandbox. However, some malware can use sandbox detection to detect that they run in such an environment and so avoid exhibiting their malicious behavior. To counteract sandbox detection, we present concolic execution that can explore several paths of a binary. We conclude by showing how opaque predicates and JIT can be used to hinder concolic execution.
Affiliations

Citations

Biondi, F., Given-Wilson, T., Legay, A., Puodzius, C., & Quilbeuf, J. (2018). Tutorial: an Overview of Malware Detection and Evasion Techniques. ISoLA. https://hdl.handle.net/2078.5/228009