2008 · 220 citations · 22 references
Malware programs that incorporate trigger-based behavior initiate malicious activities based on conditions satisfied only by specific inputs. State-of-the-art malware analyzers discover code guarded by triggers via multiple path exploration, symbolic execution, or forced conditional execution, all without knowing the trigger inputs. We present a malware obfuscation technique that automatically conceals specific trigger-based behavior from these malware analyzers. Our technique automatically transforms a program by encrypting code that is conditionally dependent on an input value with a key derived from the input and then removing the key from the program. We have implemented a compiler-level tool that takes a malware source program and automatically generates an obfuscated binary. Experiments on various existing malware samples show that our tool can hide a significant portion of trigger based code. We provide insight into the strengths, weaknesses, and possible ways to strengthen current analysis approaches in order to defeat this malware obfuscation technique. 1
22
A Taxonomy of Obfuscating Transformations
Christian Collberg, Clark Thomborson, Douglas Low · 1997 · 850 citations
The art of computer virus research and defense
Choice Reviews Online · 2005 · 841 citations
David Moore, Colleen Shannon, kc claffy · 2002 · 790 citations
Cristian Cadar, Vijay Ganesh, Peter M. Pawlowski et al. · 2006 · 784 citations