Autovac: Towards Automatically Extracting System Resource Constraints and Generating Vaccines for Malware Immunization Conference Paper uri icon

abstract

  • Malware often contains many system-resourcesensitive condition checks to avoid any duplicate infection, make sure to obtain required resources, or try to infect only targeted computers, etc. If we are able to extract the system resource constraints from malware code, and manipulate the environment state as vaccines, we would then be able to immunize a computer from infections. Towards this end, this paper provides the first systematic study and presents a prototype system, AUTOVAC, for automatically extracting the system resource constraints from malware code and generating vaccines based on the system resource conditions. Specifically, through monitoring the data propagation from system-resource-related system calls, AUTOVAC automatically identifies the environment related state of a computer. Through analyzing the environment state, AUTOVAC automatically generates vaccines. Such vaccines can be then injected into other computers, thereby being immune from future infections from the same malware or its polymorphic variants. We have evaluated AUTOVAC on a large set of real-world malware samples and successfully extracted working vaccines for many families including high-profile Conficker, Sality and Zeus. We believe AUTOVAC represents an appealing technique to complement existing malware defenses. 2013 IEEE.

name of conference

  • 2013 IEEE 33rd International Conference on Distributed Computing Systems

published proceedings

  • 2013 IEEE 33rd International Conference on Distributed Computing Systems

author list (cited authors)

  • Xu, Z., Zhang, J., Gu, G., & Lin, Z.

citation count

  • 12

complete list of authors

  • Xu, Zhaoyan||Zhang, Jialong||Gu, Guofei||Lin, Zhiqiang

publication date

  • January 2013