Automatic Malware Analysis An Emulator Based Approach

Malicious software (i.e., malware) has become a severe threat to interconnected computer systems for decades and has caused billions of dollars damages each year. A large volume of new malware samples are discovered daily. Even worse, malware is rapidly e

  • PDF / 1,288,139 Bytes
  • 83 Pages / 439.36 x 666.15 pts Page_size
  • 121 Downloads / 408 Views

DOWNLOAD

REPORT


Series Editors Stan Zdonik Peng Ning Shashi Shekhar Jonathan Katz Xindong Wu Lakhmi C. Jain David Padua Xuemin Shen Borko Furht V. S. Subrahmanian Martial Hebert Katsushi Ikeuchi Bruno Siciliano

For further volumes: http://www.springer.com/series/10028

Heng Yin • Dawn Song

Automatic Malware Analysis An Emulator Based Approach

123

Heng Yin Department of Electrical Engineering and Computer Science Syracuse University Syracuse, NY, USA

Dawn Song Computer Science Division University of California, Berkeley Berkeley, CA, USA

This book contains copyright materials from ACM and ISOC ISSN 2191-5768 ISSN 2191-5776 (electronic) ISBN 978-1-4614-5522-6 ISBN 978-1-4614-5523-3 (eBook) DOI 10.1007/978-1-4614-5523-3 Springer New York Heidelberg Dordrecht London Library of Congress Control Number: 2012945632 © The Author(s) 2013 This work is subject to copyright. All rights are reserved by the Publisher, whether the whole or part of the material is concerned, specifically the rights of translation, reprinting, reuse of illustrations, recitation, broadcasting, reproduction on microfilms or in any other physical way, and transmission or information storage and retrieval, electronic adaptation, computer software, or by similar or dissimilar methodology now known or hereafter developed. Exempted from this legal reservation are brief excerpts in connection with reviews or scholarly analysis or material supplied specifically for the purpose of being entered and executed on a computer system, for exclusive use by the purchaser of the work. Duplication of this publication or parts thereof is permitted only under the provisions of the Copyright Law of the Publisher’s location, in its current version, and permission for use must always be obtained from Springer. Permissions for use may be obtained through RightsLink at the Copyright Clearance Center. Violations are liable to prosecution under the respective Copyright Law. The use of general descriptive names, registered names, trademarks, service marks, etc. in this publication does not imply, even in the absence of a specific statement, that such names are exempt from the relevant protective laws and regulations and therefore free for general use. While the advice and information in this book are believed to be true and accurate at the date of publication, neither the authors nor the editors nor the publisher can accept any legal responsibility for any errors or omissions that may be made. The publisher makes no warranty, express or implied, with respect to the material contained herein. Printed on acid-free paper Springer is part of Springer Science+Business Media (www.springer.com)

Acknowledgements

We acknowledge the contribution made by the past and current members of the BitBlaze team, which is led by Professor Dawn Song at University of California, Berkeley, for analyzing program binaries for security applications. In addition to the authors of this book, other past and current members, including David Brumley, Juan Caballero, Cody Hartwig, Ivan Jager, Min Gyung Kang, Zhenk