USENIX Security2021Top-tier venue
When Malware Changed Its Mind: An Empirical Study of Variable Program Behaviors in the Real World
Erin Avllazagaj, Ziyun Zhu, Leyla Bilge, Davide Balzarotti, Tudor Dumitras
Abstract
Behavioral program analysis is widely used for understanding malware behavior, for creating rule-based detectors, and for clustering samples into malware families. However, this approach is ineffective when the behavior of individual samples changes across different executions, owing to environment sensitivity, evasive techniques or time variability. While the inability to observe the complete behavior of a program is a well-known limitation of dynamic analysis, the prevalence of this behavior variability in the wild, and the behavior components that are most affected by it, are still unknown. As the behavioral traces are typically collected by executing the samples in a controlled environment, the models created and tested using such traces do not account for the broad range of behaviors observed in the wild, and may result in a false sense of security. In this paper we conduct the first quantitative analysis of behavioral variability in Windows malware, PUP and benign samples, using a novel dataset of 7.6M execution traces, recorded in 5.4M real hosts from 113 countries. We analyze program behaviors at multiple granularities, and we show how they change across hosts and across time. We then analyze the invariant parts of the malware behaviors, and we show how this affects the effectiveness of malware detection using a common class of behavioral rules. Our findings have actionable implications for malware clustering and detection, and they emphasize that program behavior in the wild depends on a subtle interplay of factors that may only be observed at scale, by monitoring malware on real hosts.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext f68e07e4-19fe-470c-b254-afe04f8e7d58Cited by top-tier papers7
- Mate! Are You Really Aware? An Explainability-Guided Testing Framework for Robustness of Malware DetectorsRuoxi Sun, Minhui Xue, Gareth Tyson, Tian Dong et al.FSE 2023 · 14 citations
- PackGenome: Automatically Generating Robust YARA Rules for Accurate Malware Packer DetectionShijia Li, Jiang Ming, Pengda Qiu, Qiyuan Chen et al.CCS 2023 · 10 citations
- SCAVY: Automated Discovery of Memory Corruption Targets in Linux Kernel for Privilege EscalationErin Avllazagaj, Yonghwi Kwon, Tudor DumitrasUSENIX Security 2024 · 7 citations
- Combating Concept Drift with Explanatory Detection and Adaptation for Android Malware ClassificationYiling He, Junchi Lei, Zhan Qin, Kui Ren et al.CCS 2025 · 2 citations
- Preventing Disruption of System Backup against Ransomware AttacksYiwei Hou, Lihua Guo, Chijin Zhou, Quan Zhang et al.ISSTA 2025 · 1 citation
Builds on3
- TESSERACT: Eliminating Experimental Bias in Malware Classification across Space and TimeFeargus Pendlebury, Fabio Pierazzi, Roberto Jordaney, Johannes Kinder et al.USENIX Security 2019 · 441 citations
- Understanding Linux MalwareEmanuele Cozzi, Mariano Graziano, Yanick Fratantonio, Davide BalzarottiS&P 2018 · 203 citations
- Mind Your Own Business: A Longitudinal Study of Threats and Vulnerabilities in EnterprisesPlaton Kotzias, Leyla Bilge, Pierre-Antoine Vervier, Juan CaballeroNDSS 2019 · 43 citations
Related papers
- A Lustrum of Malware Network Communication: Evolution and InsightsChaz Lever, Platon Kotzias, Davide Balzarotti, Juan Caballero et al.S&P 2017 · 86 citations
- Does Every Second Count? Time-based Evolution of Malware Behavior in SandboxesAlexander Küchler, Alessandro Mantovani, Yufei Han, Leyla Bilge et al.NDSS 2021
- Spotless Sandboxes: Evading Malware Analysis Systems Using Wear-and-Tear ArtifactsNajmeh Miramirkhani, Mahathi Priya Appini, Nick Nikiforakis, Michalis PolychronakisS&P 2017 · 134 citations
- Decoding the Secrets of Machine Learning in Malware Classification: A Deep Dive into Datasets, Feature Extraction, and Model PerformanceSavino Dambra, Yufei Han, Simone Aonzo, Platon Kotzias et al.CCS 2023 · 28 citations
- MalMax: Multi-Aspect Execution for Automated Dynamic Web Server Malware AnalysisAbbas Naderi-Afooshteh, Yonghwi Kwon, Anh Nguyen-Tuong, Ali Razmjoo-Qalaei et al.CCS 2019 · 18 citations
