University of New Orleans
Dynamic Behavioral Analysis of Malicious Software with Norman Sandbox
Abstract
dc:description.abstract<p>Current signature-based Anti-Virus (AV) detection approaches take, on average, two weeks from discovery to definition update release to AV users. In addition, these signatures get stale quickly: AV products miss between 25%-80% of new malicious software within a week of not updating. This thesis researches and develops a detection/classification mechanism for malicious software through statistical analysis of dynamic malware behavior. Several characteristics for each behavior type were stored and analyzed such as function DLL names, function parameters, exception thread ids, exception opcodes, pages accessed during faults, port numbers, connection types, and IP addresses. Behavioral data was collected via Norman Sandbox for storage and analysis. We proposed to find which statistical measures and metrics can be collected for use in the detection and classification of malware. We conclude that our logging and cataloging procedure is a potentially viable method in creating behavior-based malicious software detection and classification mechanisms.</p>
Degree
thesis:*- Name thesis:degree_name
- M.S.
- Level thesis:degree_level
- Thesis
- Discipline thesis:degree_discipline
- Computer Science
- Year
- 2010
Author and committee
dc:creator, dc:contributor.*- Author dc:creator
-
- Shoemake, Danielle
- Contributors dc:contributor
-
- Bilar, Daniel
- Richard III, Golden
- Tu, Shengru
Subjects
dc:subject × 5Identifiers
dc:identifier.*- Repository record dc:identifier
- https://scholarworks.uno.edu/td/1233
- OAI identifier oai:identifier
- oai:scholarworks.uno.edu:td-2216