Detection of Mirai by Syntactic and Behavioral Analysis

Najah Ben Said, Fabrizio Biondi, Vesselin Bontchev, Olivier Decourbe, Thomas Given-Wilson, Axel Legay, Jean Quilbeuf

Publikation: Bidrag til bog/antologi/rapport/konference proceedingKonferenceartikel i proceedingForskningpeer review

16 Citationer (Scopus)

Abstract

The largest botnet distributed denial of service attacks in history have been executed by devices controlled by the Mirai botnet trojan. To prevent Mirai from spreading, this paper presents and evaluates techniques to classify binary samples as Mirai based on their syntactic and behavioral properties. Syntactic malware detection is shown to have a good detection rate and no false positives, but to be very easy to circumvent. Behavioral malware detection is resistant to simple obfuscation and has better detection rate than syntactic detection, while keeping false positives to zero. This paper demonstrates these results, and concludes by showing how to combine syntactic and behavioral analysis techniques for the detection of Mirai.

OriginalsprogEngelsk
TitelProceedings - 29th IEEE International Symposium on Software Reliability Engineering, ISSRE 2018
RedaktørerSudipto Ghosh, Bojan Cukic, Robin Poston, Roberto Natella, Nuno Laranjeiro
Antal sider12
ForlagIEEE Computer Society Press
Publikationsdato16 nov. 2018
Sider224-235
Artikelnummer8539084
ISBN (Trykt)978-1-5386-8322-4
ISBN (Elektronisk)978-1-5386-8321-7
DOI
StatusUdgivet - 16 nov. 2018
Begivenhed29th IEEE International Symposium on Software Reliability Engineering, ISSRE 2018 - Memphis, USA
Varighed: 15 okt. 201818 okt. 2018

Konference

Konference29th IEEE International Symposium on Software Reliability Engineering, ISSRE 2018
Land/OmrådeUSA
ByMemphis
Periode15/10/201818/10/2018
SponsorFedEx, Google, IEEE Computer Society, IEEE Reliability Society, Nokia
NavnProceedings - International Symposium on Software Reliability Engineering, ISSRE
Vol/bind2018-October
ISSN1071-9458

Fingeraftryk

Dyk ned i forskningsemnerne om 'Detection of Mirai by Syntactic and Behavioral Analysis'. Sammen danner de et unikt fingeraftryk.

Citationsformater