Skip to main navigation Skip to search Skip to main content

MAS: Malware analysis system based on hardware-assisted virtualization technology

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

There are many analysis techniques in order to analyze malicious codes. However, recently malicious codes often evade detection using stealthy obfuscation techniques, and attack computing systems. We propose an enhanced dynamic binary instrumentation using hardware-assisted virtualization technology. As a machine-level analyzer, our system can be isolated from almost the whole threats of malware, and provides single step analysis environment. Proposed system also supports rapid system call analysis environment. We implement our malware analysis system (referred as MAS) on the KVM hypervisor with Intel VT-x virtualization support. Our experiments with benchmarks show that the proposed system provides efficient analysis environment with low overhead.

Original languageEnglish
Title of host publicationSecurity Technology, Disaster Recovery and Business Continuity - International Conferences, SecTech and DRBC 2010, Held as Part of the Future Generation Information Technology Conference, FGIT 2010
Pages134-141
Number of pages8
DOIs
StatePublished - 2010
Event2010 International Conferences on Security Technology, SecTech 2010 and Disaster Recovery and Business Continuity, DRBC 2010, Held as Part of the 2nd International Mega-Conference on Future Generation Information Technology, FGIT 2010 - Jeju Island, Korea, Republic of
Duration: 13 Dec 201015 Dec 2010

Publication series

NameCommunications in Computer and Information Science
Volume122 CCIS
ISSN (Print)1865-0929

Conference

Conference2010 International Conferences on Security Technology, SecTech 2010 and Disaster Recovery and Business Continuity, DRBC 2010, Held as Part of the 2nd International Mega-Conference on Future Generation Information Technology, FGIT 2010
Country/TerritoryKorea, Republic of
CityJeju Island
Period13/12/1015/12/10

Keywords

  • Dynamic Binary Instrumentation
  • Intel VT
  • KVM
  • Malware
  • Virtualization Technology

Fingerprint

Dive into the research topics of 'MAS: Malware analysis system based on hardware-assisted virtualization technology'. Together they form a unique fingerprint.

Cite this