Software transformations to improve malware detection. / Christodorescu, Mihai; Jha, Somesh; Kinder, Johannes; Katzenbeisser, Stefan; Veith, Helmut.

In: Journal in Computer Virology, Vol. 3, No. 4, 2007, p. 253-265.

Research output: Contribution to journalArticle

Published

Documents

  • jicv07

    Accepted author manuscript, 306 KB, PDF document

  • Mihai Christodorescu
  • Somesh Jha
  • Johannes Kinder
  • Stefan Katzenbeisser
  • Helmut Veith

Abstract

Malware is code designed for a malicious purpose, such as obtaining root privilege on a host. A malware detector identifies malware and thus prevents it from adversely affecting a host. In order to evade detection, malware writers use various obfuscation techniques to transform their malware. There is strong evidence that commercial malware detectors are susceptible to these evasion tactics. In this paper, we describe the design and implementation of a malware transformer that reverses the obfuscations performed by a malware writer. Our experimental evaluation demonstrates that this malware transformer can drastically improve the detection rates of commercial malware detectors.
Original languageEnglish
Pages (from-to)253-265
JournalJournal in Computer Virology
Volume3
Issue number4
DOIs
Publication statusPublished - 2007
This open access research output is licenced under a Creative Commons Attribution-NonCommercial-NoDerivs 3.0 Unported License.

ID: 17566543