Abstraction by Term Rewriting for Malware Behavior Analysis - Extended Version - INRIA - Institut National de Recherche en Informatique et en Automatique Accéder directement au contenu
Rapport (Rapport De Recherche) Année : 2010

Abstraction by Term Rewriting for Malware Behavior Analysis - Extended Version

Résumé

We propose a formal approach for behavioral analysis of programs based on dynamic analysis. It works by abstracting execution traces with respect to given behavior patterns in order to produce a high level representation of a program behavior and then, by comparing this abstract form to signatures defining reference abstract malicious behaviors. Abstraction is performed by term rewriting using rules on terms with variables, which enables to handle the data used by behavior functionalities. This technique allows us to deal with interleaved behaviors. Successfully applied to malware detection, it allows us in particular to model and detect information leak.
Fichier principal
Vignette du fichier
article-extended.pdf (293.4 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)
Loading...

Dates et versions

inria-00547884 , version 1 (17-12-2010)
inria-00547884 , version 2 (19-12-2010)
inria-00547884 , version 3 (05-01-2011)

Identifiants

  • HAL Id : inria-00547884 , version 3

Citer

Philippe Beaucamps, Isabelle Gnaedig, Jean-Yves Marion. Abstraction by Term Rewriting for Malware Behavior Analysis - Extended Version. [Research Report] 2010. ⟨inria-00547884v3⟩
172 Consultations
142 Téléchargements

Partager

Gmail Facebook X LinkedIn More