Publication | Closed Access
MARD: A Framework for Metamorphic Malware Analysis and Real-Time Detection
25
Citations
44
References
2014
Year
Unknown Venue
EngineeringEvasion TechniqueInformation SecuritySoftware EngineeringSoftware AnalysisHardware SecurityData ScienceMetamorphic Malware AnalysisComputer EngineeringMetaprogrammingMobile MalwareComputer ScienceMetamorphic MalwareData SecurityReal-time Malware DetectionMalware IndustrySoftware SecurityProgram AnalysisSoftware TestingAnti-virus TechniqueMalware Analysis
Because of the financial and other gains attached with the growing malware industry, there is a need to automate the process of malware analysis and provide real-time malware detection. To hide a malware, obfuscation techniques are used. One such technique is metamorphism encoding that mutates the dynamic binary code and changes the opcode with every run to avoid detection. This makes malware difficult to detect in real-time and generally requires a behavioral signature for detection. In this paper we present a new framework called MARD for Metamorphic Malware Analysis and Real-Time Detection, to protect the end points that are often the last defense, against metamorphic malware. MARD provides: (1) automation (2) platform independence (3) optimizations for real-time performance and (4) modularity. We also present a comparison of MARD with other such recent efforts. Experimental evaluation of MARD achieves a detection rate of 99.6% and a false positive rate of 4%.
| Year | Citations | |
|---|---|---|
Page 1
Page 1