Host-Based Malware Variants Detection Method Using Logs


Woo-Jin Joe, Hyong-Shik Kim, Journal of Information Processing Systems Vol. 17, No. 4, pp. 851-865, Aug. 2021  

https://doi.org/10.3745/JIPS.03.0163
Keywords: Big data, Host-Based Detection, log, Malware Variants, Sysmon
Fulltext:

Abstract

Enterprise networks in the PyeongChang Winter Olympics were hacked in February 2018. According to a domestic security company’s analysis report, attackers destroyed approximately 300 hosts with the aim of interfering with the Olympics. Enterprise have no choice but to rely on digital vaccines since it is overwhelming to analyze all programs executed in the host used by ordinary users. However, traditional vaccines cannot protect the host against variant or new malware because they cannot detect intrusions without signatures for malwares. To overcome this limitation of signature-based detection, there has been much research conducted on the behavior analysis of malwares. However, since most of them rely on a sandbox where only analysis target program is running, we cannot detect malwares intruding the host where many normal programs are running. Therefore, this study proposes a method to detect malware variants in the host through logs rather than the sandbox. The proposed method extracts common behaviors from variants group and finds characteristic behaviors optimized for querying. Through experimentation on 1,584,363 logs, generated by executing 6,430 malware samples, we prove that there exist the common behaviors that variants share and we demonstrate that these behaviors can be used to detect variants.


Statistics
Show / Hide Statistics

Statistics (Cumulative Counts from November 1st, 2017)
Multiple requests among the same browser session are counted as one view.
If you mouse over a chart, the values of data points will be shown.




Cite this article
[APA Style]
Joe, W. & Kim, H. (2021). Host-Based Malware Variants Detection Method Using Logs. Journal of Information Processing Systems, 17(4), 851-865. DOI: 10.3745/JIPS.03.0163.

[IEEE Style]
W. Joe and H. Kim, "Host-Based Malware Variants Detection Method Using Logs," Journal of Information Processing Systems, vol. 17, no. 4, pp. 851-865, 2021. DOI: 10.3745/JIPS.03.0163.

[ACM Style]
Woo-Jin Joe and Hyong-Shik Kim. 2021. Host-Based Malware Variants Detection Method Using Logs. Journal of Information Processing Systems, 17, 4, (2021), 851-865. DOI: 10.3745/JIPS.03.0163.