Extended Abstract: Evading Packing Detection: Breaking Heuristic-Based Static Detectors

被引:0
|
作者
D'Hondt, Alexandre [1 ]
Van Ouytsel, Charles Henry Bertrand [1 ]
Legay, Axel [1 ]
机构
[1] Catholic Univ Louvain, Rue Archimede 1, Louvain La Neuve, Belgium
关键词
executable packing; packer detection; static analysis; adversarial examples; experimental toolkit; ENTROPY ANALYSIS;
D O I
10.1007/978-3-031-64171-8_9
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Nowadays, executable packing remains an open issue in its detection especially when it comes to static analysis. Packing is significantly used in malware to hide malicious code from detection systems. These last years, many studies about static packing detection addressed this problem with heuristics and machine learning, considering different ad hoc techniques, algorithms and feature sets but very few addressed it from the adversarial point of view, that is, how to fool heuristics by altering samples with targeted modifications. The objective of this work is to study to what extent it is easy to evade detection by open source static detectors that are commonly used by the community by applying alterations on packed samples, which require only slight adaptations of the related packers, resulting in evasion. An adversarial setting from the problem-space perspective is addressed by using realistic modifications of binary samples that target common significant features. For this purpose, alterations and datasets are composed and static detection is applied using the experimental toolkit Packing Box. Results of alterations are shown, in terms of information gain of features and accuracy of detection, on open source static packing detectors. Finally, their significant effects are highlighted and their effectiveness is evaluated.
引用
收藏
页码:174 / 183
页数:10
相关论文
共 40 条
  • [1] Botnets: A Heuristic-Based Detection Framework
    Mendonca, Luis
    Santos, Henrique
    PROCEEDINGS OF THE FIFTH INTERNATIONAL CONFERENCE ON SECURITY OF INFORMATION AND NETWORKS, 2012, : 33 - 40
  • [2] THE LAST ALGORITHM - A HEURISTIC-BASED STATIC TASK ALLOCATION ALGORITHM
    BAXTER, J
    PATEL, JH
    PROCEEDINGS OF THE 1989 INTERNATIONAL CONFERENCE ON PARALLEL PROCESSING, VOL 2: SOFTWARE, 1989, : 217 - 222
  • [3] CaseID Detection for Process Mining: A Heuristic-Based Methodology
    De Fazio, Roberta
    Balzanella, Antonio
    Marrone, Stefano
    Marulli, Fiammetta
    Verde, Laura
    Reccia, Vincenzo
    Valletta, Paolo
    PROCESS MINING WORKSHOPS, ICPM 2023, 2024, 503 : 45 - 57
  • [4] Heuristic-based approaches for fracture detection in borehole images
    Moran M.B.H.
    Vasconcellos E.C.
    Cuno J.J.S.
    Biondi M.
    Riveaux J.M.
    Correia M.D.
    Gonzalez Clua E.W.
    Conci A.
    International Journal of Innovative Computing and Applications, 2023, 14 (1-2) : 78 - 90
  • [5] Evading Anomaly Detection through Variance Injection Attacks on PCA (Extended Abstract)
    Rubinstein, Benjamin I. P.
    Nelson, Blaine
    Huang, Ling
    Joseph, Anthony D.
    Lau, Shing-hon
    Taft, Nina
    Tygar, J. D.
    RECENT ADVANCES IN INTRUSION DETECTION, RAID 2008, 2008, 5230 : 394 - +
  • [6] A Heuristic-Based Reduction for the Temporal Bin Packing Problem with Fire-Ups
    Martinovic, John
    Strasdat, Nico
    OPERATIONS RESEARCH PROCEEDINGS 2021, 2022, : 127 - 133
  • [7] Online Phishing Detection: A Heuristic-Based Machine Learning Framework
    Elgharbi, Salah Eddine
    Yahia, Messaoud Ait
    Ouchani, Samir
    2024 13TH MEDITERRANEAN CONFERENCE ON EMBEDDED COMPUTING, MECO 2024, 2024, : 302 - 305
  • [8] Hybrid Android Malware Detection: A Review of Heuristic-Based Approach
    Yunmar, Rajif Agung
    Kusumawardani, Sri Suning
    Mohsen, Fadi
    IEEE ACCESS, 2024, 12 : 41255 - 41286
  • [9] Heuristic-based energy landscape paving for the circular packing problem with performance constraints of equilibrium
    Liu, Jingfa
    Jiang, Yucong
    Li, Gang
    Xue, Yu
    Liu, Zhaoxia
    Zhang, Zhen
    PHYSICA A-STATISTICAL MECHANICS AND ITS APPLICATIONS, 2015, 431 : 166 - 174
  • [10] Color and heuristic-based Face Detection in H.264 Video sequences
    Nam, Chol-Man
    Ruan, QiuQi
    An, GaoYun
    2010 IEEE 10TH INTERNATIONAL CONFERENCE ON SIGNAL PROCESSING PROCEEDINGS (ICSP2010), VOLS I-III, 2010, : 1288 - 1292