USENIX Security2021Top-tier venue
Forecasting Malware Capabilities From Cyber Attack Memory Images
Omar Alrawi, Moses Ike, Matthew Pruett, Ranjita Pai Kasturi, Srimanta Barua, Taleb Hirani, Brennan Hill, Brendan Saltaformaggio
Abstract
The remediation of ongoing cyber attacks relies upon timely malware analysis, which aims to uncover malicious functionalities that have not yet executed. Unfortunately, this requires repeated context switching between different tools and incurs a high cognitive load on the analyst, slowing down the investigation and giving attackers an advantage. We present Forecast, a post-detection technique to enable incident responders to automatically predict capabilities which malware have staged for execution. Forecast is based on a probabilistic model that allows Forecast to discover capabilities and also weigh each capability according to its relative likelihood of execution (i.e., forecasts). Forecast leverages the execution context of the ongoing attack (from the malware's memory image) to guide a symbolic analysis of the malware's code. We performed extensive evaluations, with 6,727 real-world malware and futuristic attacks aiming to subvert Forecast, showing the accuracy and robustness in predicting malware capabilities. on this idea, we propose seeding the symbolic exploration of a malware's pre-staged paths with concrete execution state obtained via memory image forensics. Through this, we overcome the previous painstaking and cognitively burdensome process that an analyst must undertake. We present Forecast, a post-detection technique to enable incident responders to forecast what capabilities are possible from a captured memory image. Forecast ranks each discovered capability according to its probability of execution (i.e., forecasts) to enable analysts to prioritize their remediation workflows. To calculate this probability, Forecast weighs each path's relative usage of concrete data. This approach is based on a formal model of the degree of concreteness (or D C (s)) of a memory image execution state (s). Starting from the last instruction pointer (IP) value in the memory image, Forecast explores each path by symbolically executing the CPU semantics of each instruction. During this exploration, Forecast models how the mixing of symbolic and concrete data influences path generation and selection. Based on this mixing, a "concreteness" score is calculated for each state along a path to derive forecast percentages for each discovered capability. D C (s) also optimizes symbolic analysis by dynamically adapting loop bounds, handling symbolic control flow, and pruning paths to reduce path explosion. To automatically identify each capability, we developed several modular capability analysis plugins: Code Injection, File Exfiltration, Dropper, Persistence, Key & Screen Spying, Anti-Analysis, and C&C URL Connection. Each plugin defines a given capability in terms of API sequences, their arguments, and how their input and output constraints connect each API. Forecast plugins are portable and can easily be extended to capture additional capabilities based on the target system's APIs. It is worth noting that Forecast's analysis only requires a forensic memory image, allowing it to work for fileless malware, making it well-suited for incident response. We evaluated Forecast with memory images of 6,727 real-world malware (including packed and unpacked) covering 274 families. Forecast renders accurate capability forecasts compared to reports produced manually by human experts. Further, we show that Forecast is robust against futuristic attacks that aim to subvert Forecast. We show that Forecast's post-detection forecasts are accurately induced by early concrete inputs. We empirically compared Forecast to S2E [6], angr [22], and Triton [23] and found that Forecast outperforms them in identifying capabilities and reducing path explosion. Forecast is available online at: https://cyfi.ece.gatech.edu/ .
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 520a9f06-53d6-48e4-a613-0eaed1d830b1Cited by top-tier papers10
- Exposing the Rat in the Tunnel: Using Traffic Analysis for Tor-based Malware DetectionPriyanka Dodia, Mashael AlSabah, Omar Alrawi, Tao WangCCS 2022 · 31 citations
- SYMBEXCEL: Automated Analysis and Understanding of Malicious Excel 4.0 MacrosNicola Ruaro, Fabio Pagani, Stefano Ortolani, Christopher Kruegel et al.S&P 2022 · 12 citations
- DVa: Extracting Victims and Abuse Vectors from Android Accessibility MalwareHaichuan Xu, Mingxuan Yao, Runze Zhang, Mohamed Moustafa Dawoud et al.USENIX Security 2024 · 10 citations
- C3PO: Large-Scale Study Of Covert Monitoring of C&C Servers via Over-Permissioned Protocol InfiltrationJonathan Fuller, Ranjita Pai Kasturi, Amit Kumar Sikder, Haichuan Xu et al.CCS 2021 · 6 citations
- Hitchhiking Vaccine: Enhancing Botnet Remediation With Remote Code Deployment ReuseRunze Zhang, Mingxuan Yao, Haichuan Xu, Omar Alrawi et al.NDSS 2025
Builds on10
- SOK: (State of) The Art of War: Offensive Techniques in Binary AnalysisYan Shoshitaishvili, Ruoyu Wang, Christopher Salls, Nick Stephens et al.S&P 2016 · 1,085 citations
- HOLMES: Real-Time APT Detection through Correlation of Suspicious Information FlowsSadegh Momeni Milajerdi, Rigel Gjomemo, Birhanu Eshete, R. Sekar et al.S&P 2019 · 550 citations
- QSYM : A Practical Concolic Execution Engine Tailored for Hybrid FuzzingInsu Yun, Sangho Lee, Meng Xu, Yeongjin Jang et al.USENIX Security 2018 · 537 citations
- NoDoze: Combatting Threat Alert Fatigue with Automated Provenance TriageWajih Ul Hassan, Shengjian Guo, Ding Li, Zhengzhang Chen et al.NDSS 2019 · 411 citations
- Tactical Provenance Analysis for Endpoint Detection and Response SystemsWajih Ul Hassan, Adam Bates, Daniel MarinoS&P 2020 · 317 citations
Related papers
- C^2SR: Cybercrime Scene Reconstruction for Post-mortem Forensic AnalysisYonghwi Kwon, Weihang Wang, Jinho Jung, Kyu Hyung Lee et al.NDSS 2021
- PMP: Cost-effective Forced Execution with Probabilistic Memory Pre-planningWei You, Zhuo Zhang, Yonghwi Kwon, Yousra Aafer et al.S&P 2020 · 29 citations
- Incident Response Planning Using a Lightweight Large Language Model with Reduced HallucinationKim Hammar, Tansu Alpcan, Emil C. LupuNDSS 2026 · 16 citations
- Combating Dependence Explosion in Forensic Analysis Using Alternative Tag Propagation SemanticsMd Nahid Hossain, Sanaz Sheikhi, R. SekarS&P 2020 · 179 citations
- Predicting the Resilience of Obfuscated Code Against Symbolic Execution Attacks via Machine LearningSebastian Banescu, Christian S. Collberg, Alexander PretschnerUSENIX Security 2017 · 55 citations
