Detection of Mirai by Syntactic and Behavioral Analysis

Najah Ben Said, Fabrizio Biondi, Vesselin Bontchev, Olivier Decourbe, Thomas Given-Wilson, Axel Legay, Jean Quilbeuf

Research output: Contribution to book/anthology/report/conference proceedingArticle in proceedingResearchpeer-review

16 Citations (Scopus)

Abstract

The largest botnet distributed denial of service attacks in history have been executed by devices controlled by the Mirai botnet trojan. To prevent Mirai from spreading, this paper presents and evaluates techniques to classify binary samples as Mirai based on their syntactic and behavioral properties. Syntactic malware detection is shown to have a good detection rate and no false positives, but to be very easy to circumvent. Behavioral malware detection is resistant to simple obfuscation and has better detection rate than syntactic detection, while keeping false positives to zero. This paper demonstrates these results, and concludes by showing how to combine syntactic and behavioral analysis techniques for the detection of Mirai.

Original languageEnglish
Title of host publicationProceedings - 29th IEEE International Symposium on Software Reliability Engineering, ISSRE 2018
EditorsSudipto Ghosh, Bojan Cukic, Robin Poston, Roberto Natella, Nuno Laranjeiro
Number of pages12
PublisherIEEE Computer Society Press
Publication date16 Nov 2018
Pages224-235
Article number8539084
ISBN (Print)978-1-5386-8322-4
ISBN (Electronic)978-1-5386-8321-7
DOIs
Publication statusPublished - 16 Nov 2018
Event29th IEEE International Symposium on Software Reliability Engineering, ISSRE 2018 - Memphis, United States
Duration: 15 Oct 201818 Oct 2018

Conference

Conference29th IEEE International Symposium on Software Reliability Engineering, ISSRE 2018
Country/TerritoryUnited States
CityMemphis
Period15/10/201818/10/2018
SponsorFedEx, Google, IEEE Computer Society, IEEE Reliability Society, Nokia
SeriesProceedings - International Symposium on Software Reliability Engineering, ISSRE
Volume2018-October
ISSN1071-9458

Keywords

  • Behavioral analysis
  • Graph mining
  • Malware
  • Mirai
  • Syntactic analysis
  • System call dependency graph
  • Yara

Fingerprint

Dive into the research topics of 'Detection of Mirai by Syntactic and Behavioral Analysis'. Together they form a unique fingerprint.

Cite this