Capturing Malware Propagations with Code Injections and Code-Reuse Attacks
David Korczynski, Heng Yin
摘要
Defending against malware involves analysing large amounts of suspicious samples. To deal with such quantities we rely heavily on automatic approaches to determine whether a sample is malicious or not. Unfortunately, complete and precise automatic analysis of malware is far from an easy task. is is because malware is o en designed to contain several techniques and countermeasures speci cally to hinder analysis. One of these techniques is for the malware to propagate through the operating system so as to execute in the context of benign processes. e malware does this by writing memory to a given process and then proceeds to have this memory execute. In some cases these propagations are trivial to capture because they rely on well-known techniques. However, in the cases where malware deploys novel code injection techniques, rely on code-reuse a acks and potentially deploy dynamically generated code, the problem of capturing a complete and precise view of the malware execution is non-trivial. In this paper we present a uni ed approach to tracing malware propagations inside the host in the context of code injections and code-reuse a acks. We also present, to the knowledge of the authors, the rst approach to identifying dynamically generated code based on information-ow analysis. We implement our techniques in a system called Tartarus and match Tartarus with both synthetic applications and real-world malware. We compare Tartarus to previous works and show that our techniques substantially improve the precision for collecting malware execution traces, and that our approach can capture intrinsic characteristics of novel code injection techniques.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper7
- SIRAJ: A Unified Framework for Aggregation of Malicious Entity DetectorsSaravanan Thirumuruganathan, Mohamed Nabeel, Euijin Choo, Issa Khalil 等S&P 2022 · 被引用 13 次
- Deep Learning from Imperfectly Labeled Malware DataFahad Alotaibi, Euan Goodbrand, Sergio MaffeisCCS 2025
- MULCOTAINT: Towards Efficient Multi-tag Dynamic Taint Analysis via Hardware/Software Co-designBing Qi, Yi Yang, Xiangkun Jia, Zhengpin Qian 等USENIX Security 2026
- Measuring and Modeling the Label Dynamics of Online Anti-Malware EnginesShuofei Zhu, Jianjun Shi, Limin Yang, Boqin Qin 等USENIX Security 2020
- You Are What You Do: Hunting Stealthy Malware via Data Provenance AnalysisQi Wang, Wajih Ul Hassan, Ding Li, Kangkook Jee 等NDSS 2020
相关 Paper
- IntelliDroid: A Targeted Input Generator for the Dynamic Analysis of Android MalwareMichelle Y. Wong, David LieNDSS 2016 · 被引用 253 次
- A Novel Dynamic Analysis Infrastructure to Instrument Untrusted Execution Flow Across User-Kernel SpacesJiaqi Hong, Xuhua DingS&P 2021 · 被引用 10 次
- A Generic Technique for Automatically Finding Defense-Aware Code Reuse AttacksEdward J. Schwartz, Cory F. Cohen, Jeffrey Gennari, Stephanie SchwartzCCS 2020 · 被引用 8 次
- Harvesting Runtime Values in Android Applications That Feature Anti-Analysis TechniquesSiegfried Rasthofer, Steven Arzt, Marc Miltenberger, Eric BoddenNDSS 2016 · 被引用 157 次
- Fine-Grained Kernel Auditing Using Augmented Syscall Reference Behavior Analysis and Virtualized Selective TracingChuqi Zhang, Spencer Faith, Feras Al-Qassas, Theodorus Februanto 等S&P 2026
