Mining Network Behavior Specifications of Malware Based on Binary Analysis

peidai xie,yongjun wang,huabiao lu,meijian li,jinshu su
DOI: https://doi.org/10.1007/978-3-642-53959-6_22
2013-01-01
Abstract:Nowadays, malware, especially for a botnet, heavily employs network communication to accomplish predefined malicious functionalities. The network behavior of malware attracts attention of researchers. However, the network traffic used for network-based signatures generation and botnet detection is captured passively from an execution environment, that there are several limitations. In this paper, we present a network behavior mining approach based on binary analysis, named NBSBA. Our goal is to accurately understand the network behavior of malware in details, capture the packets the malware sample under analysis launched as soon as possible, and extract network behavior of malware as completely as possible. We firstly give a network behavior specification and then describe the NBSBA. And we implement a prototype system to evaluate the NBSBA. The experiment demonstrates that our approach is efficient.
What problem does this paper attempt to address?