Abstract:
One challenge in malware analysis involves collecting useful data without risking experimenters' machines or systems. Static analysis of malware codebases is valuable in ...Show MoreMetadata
Abstract:
One challenge in malware analysis involves collecting useful data without risking experimenters' machines or systems. Static analysis of malware codebases is valuable in providing insights on malware development mechanisms, however, it cannot provide understanding in dynamic profiling of executable codes. In this paper, we present a case study of the well-known Nugache worm using existing reverse engineering tools to collect data from malwares running in a closed-lab environment. Useful dynamic patterns of malwares are generated by using a rough set based machine learning tool. The proposed approach can be used for the study of malware behaviors in a safe and pedagogical environment. The dynamic patterns generated by data mining tools may provide insights for specifying similarity measures used by network level Intrusion Detection Systems.
Date of Conference: 01-03 July 2010
Date Added to IEEE Xplore: 19 August 2010
ISBN Information:
ISSN Information:
Keywords assist with retrieval of results and provide a means to discovering other relevant content. Learn more.
- IEEE Keywords
- Index Terms
- Data Mining ,
- Reverse Engineering ,
- Data Mining Tools ,
- Machine Learning Tools ,
- Intrusion Detection ,
- Intrusion Detection System ,
- Operating System ,
- Computer Program ,
- Web Page ,
- Digital Networks ,
- Decision Rules ,
- Alarming Rate ,
- Network Flow ,
- Virtual Machines ,
- Knowledge Users ,
- Peer Networks ,
- Central Server ,
- Central Command ,
- P2P Network ,
- Registry Entry ,
- Attack Vector ,
- Security Solutions ,
- Uniform Resource Locator ,
- Internet Explorer ,
- Windows Operating System ,
- Data Mining Applications
- Author Keywords
- malware ,
- botnet ,
- P2P ,
- reverse engineering ,
- data mining
Keywords assist with retrieval of results and provide a means to discovering other relevant content. Learn more.
- IEEE Keywords
- Index Terms
- Data Mining ,
- Reverse Engineering ,
- Data Mining Tools ,
- Machine Learning Tools ,
- Intrusion Detection ,
- Intrusion Detection System ,
- Operating System ,
- Computer Program ,
- Web Page ,
- Digital Networks ,
- Decision Rules ,
- Alarming Rate ,
- Network Flow ,
- Virtual Machines ,
- Knowledge Users ,
- Peer Networks ,
- Central Server ,
- Central Command ,
- P2P Network ,
- Registry Entry ,
- Attack Vector ,
- Security Solutions ,
- Uniform Resource Locator ,
- Internet Explorer ,
- Windows Operating System ,
- Data Mining Applications
- Author Keywords
- malware ,
- botnet ,
- P2P ,
- reverse engineering ,
- data mining