skip to main content
10.1145/2490428.2490442acmconferencesArticle/Chapter ViewAbstractPublication PagessecuritConference Proceedingsconference-collections
research-article

SPADE: Signature based PAcker DEtection

Authors Info & Claims
Published:17 August 2012Publication History

ABSTRACT

Malware is a powerful weapon to hamper various confidential and secure data of a personal computer. Code packing helps the malware authors to create new variants of existing malwares and thus signature based malware detection is defeated. Packing tools hinder the reverse engineering process and hence it is difficult for security researchers to perform analysis of new or unknown malware. Dynamic unpacker requires dedicated hardware and software for analyzing samples and it is computationally expensive. Hence a fast method is required for analysing packers used to create packed executable. Every packer uses its own unpacking algorithm to unpack the payload in memory, so if apriori information on packer used is available, the unpacking becomes easy. In this paper, we have proposed a novel technique for generating the signature of packed malware to identify the packer used for obfuscating the binary.

References

  1. ASPack. http://www.aspack.com/, Last Accessed October 2011.Google ScholarGoogle Scholar
  2. Exe32pack. http://www.softpedia.com/get/System/File-Management/exe32pack.shtml, Last Accessed October 2011.Google ScholarGoogle Scholar
  3. Faster Universal Unpacker. http://fuuproject.wordpress.com/tag/faster-universal-unpacker/, Last Accessed November 2011.Google ScholarGoogle Scholar
  4. GUnPacker. http://leechermods.com, Last Accessed November 2011.Google ScholarGoogle Scholar
  5. NsPack. http://www.brothersoft.com/nspack-199395.html, Last Accessed October 2011.Google ScholarGoogle Scholar
  6. OllyDbg. http://www.ollydbg.de/, Last Accessed November 2011.Google ScholarGoogle Scholar
  7. PECompact. http://www.bitsum.com/pecompact.php, Last Accessed October 2011.Google ScholarGoogle Scholar
  8. PEtite. http://www.softpedia.com/get/Programming/Other-Programming-Files/Petite.shtml, Last Accessed October 2011.Google ScholarGoogle Scholar
  9. UPX. http://upx.sourceforge.net/, Last Accessed October 2011.Google ScholarGoogle Scholar
  10. VMUnpacker. http://www.woodman.co, Last Accessed November 2011.Google ScholarGoogle Scholar
  11. Detect it Easy. http://reversingtools.blogspot.in/2009/11/detect-it-easy-die-v064.html, Last Accessed January 2012.Google ScholarGoogle Scholar
  12. Malware. http://www.mashable.com/follow/topics/malware/, Last Accessed May 2012.Google ScholarGoogle Scholar
  13. Phylogenetics. http://www.cs.princeton.edu/~mona/Lecture/msa1.pdf, Last Accessed March 2012.Google ScholarGoogle Scholar
  14. ProtectioniD. http://protectionid.owns.it/, Last Accessed January 2012.Google ScholarGoogle Scholar
  15. D. Balzarotti, M. Cova, C. Karlberger, C. Kruegel, E. Kirda, and G. Vigna. Efficient Detection of Split Personalities in Malware.Google ScholarGoogle Scholar
  16. A. Dinaburg, P. Royal, M. Sharif, and W. Lee. Ether:Malware Analysis via Hardware Virtualization Extensions. In Proceedings of the 15th ACM conference on Computer and communications security, CCS '08, pages 51--62. ACM, 2008. Google ScholarGoogle ScholarDigital LibraryDigital Library
  17. exeInfo. http://www.exeinfo.xwp.pl/., Last Accessed January 2012.Google ScholarGoogle Scholar
  18. M. G. Kang, P. Poosankam, and H. Yin. Renovo: A Hidden Code Extractor for Packed Executables. In Proceedings of the 2007 ACM workshop on Recurring malcode, WORM '07, pages 46--53, New York, NY, USA, 2007. ACM. Google ScholarGoogle ScholarDigital LibraryDigital Library
  19. L. Martignoni, M. Christodorescu, and S. Jha. Omniunpack: Fast, generic, and safe unpacking of malware. In In Proceedings of the Annual Computer Security Applications Conference (ACSAC), 2007.Google ScholarGoogle ScholarCross RefCross Ref
  20. McAfee. The Good, the Bad, the Unknown.Google ScholarGoogle Scholar
  21. PEiD. Packed Executable IDentification. http://www.peid.info/., Last Accessed January 2012.Google ScholarGoogle Scholar
  22. RDGMax. RDG Packer Detector. http://rdgsoft.8k.com/, Last Accessed January 2012.Google ScholarGoogle Scholar
  23. P. Royal, M. Halpin, D. Dagon, R. Edmonds, and W. Lee. PolyUnpack: Automating the Hidden-Code Extraction of Unpack-Executing Malware. In Proceedings of the 22nd Annual Computer Security Applications Conference, ACSAC '06, pages 289--300, Washington, DC, USA, 2006. IEEE Computer Society. Google ScholarGoogle ScholarDigital LibraryDigital Library
  24. I. Santos, X. Ugarte-Pedrero, B. Sanz, C. Laorden, and P. G. Bringas. Collective classification for packed executable identification. In Proceedings of the 8th Annual Collaboration, Electronic messaging, Anti-Abuse and Spam Conference, CEAS '11, pages 23--30, New York, NY, USA, 2011. ACM. Google ScholarGoogle ScholarDigital LibraryDigital Library
  25. M. Z. Shafiq, S. M. Tabish, F. Mirza, and M. Farooq. PE-Miner: Mining Structural Information to Detect Malicious Executables in Realtime. In Proceedings of the 12th International Symposium on Recent Advances in Intrusion Detection, RAID '09, pages 121--141, Berlin, Heidelberg, 2009. Springer-Verlag. Google ScholarGoogle ScholarDigital LibraryDigital Library
  26. D. Shin, C. Im, H. Jeong, S. Kim, and D. Won. The new signature generation method based on an unpacking algorithm and procedure for a packer detection. In International Journal of Advanced Science and Technology, volume 27, pages 59--78, 2011.Google ScholarGoogle Scholar
  27. T. F. Smith and M. S. Waterman. Identification of common molecular subsequences. Journal of Molecular Biology, 147(1):195--197, 1981.Google ScholarGoogle ScholarCross RefCross Ref
  28. J. Stewart. OllyBonE v0.1, Break-On-Execute for OllyDbg. http://www.joestewart.org/, Last Accessed November 2011.Google ScholarGoogle Scholar
  29. X. Ugarte-Pedrero, I. Santos, and P. G. Bringas. Structural feature based anomaly detection for packed executable identification. In Proceedings of the 4th international conference on Computational intelligence in security for information systems, CISIS'11, pages 230--237, Berlin, Heidelberg, 2011. Springer-Verlag. Google ScholarGoogle ScholarDigital LibraryDigital Library
  30. P. Vinod, V. Laxmi, M. S. Gaur, and G. Chauhan. MOMENTUM: MetamOrphic Malware Exploration Techniques Using MSA signatures. In Proceedings of the Eight International Conference on Innovations in Information Technology, AL AIN, Abu Dhabi, UAE, April 2012.Google ScholarGoogle ScholarCross RefCross Ref
  31. VirusTotal. Free Software Downloads and Software Reviews. https://www.virustotal.com/, Last Accessed November 2011.Google ScholarGoogle Scholar
  32. VXHeavens. Virus Collections (VXheavens). http://vl.netlux.org/vl.php/, Last Accessed August 2011.Google ScholarGoogle Scholar

Index Terms

  1. SPADE: Signature based PAcker DEtection

      Recommendations

      Comments

      Login options

      Check if you have access through your login credentials or your institution to get full access on this article.

      Sign in
      • Published in

        cover image ACM Conferences
        SecurIT '12: Proceedings of the First International Conference on Security of Internet of Things
        August 2012
        266 pages
        ISBN:9781450318228
        DOI:10.1145/2490428

        Copyright © 2012 ACM

        Permission to make digital or hard copies of all or part of this work for personal or classroom use is granted without fee provided that copies are not made or distributed for profit or commercial advantage and that copies bear this notice and the full citation on the first page. Copyrights for components of this work owned by others than ACM must be honored. Abstracting with credit is permitted. To copy otherwise, or republish, to post on servers or to redistribute to lists, requires prior specific permission and/or a fee. Request permissions from [email protected]

        Publisher

        Association for Computing Machinery

        New York, NY, United States

        Publication History

        • Published: 17 August 2012

        Permissions

        Request permissions about this article.

        Request Permissions

        Check for updates

        Qualifiers

        • research-article

      PDF Format

      View or Download as a PDF file.

      PDF

      eReader

      View online with eReader.

      eReader