Screening Legitimate and Fake/Crude Antivirus Software
スポンサーリンク
概要
- 論文の詳細を見る
Fake antivirus (AV) software, a kind of malware, pretends to be a legitimate AV product and frightens computer users by showing fake security alerts, as if their computers were infected with malware. In addition, fake AV urges users to purchase a "commercial" version of the fake AV. In this paper, we search for an indicato that captures behavioral differences in legitimate AV and fake AV. The key insight behind our approach is that legitimate AV behaves differently in clean and infected environments, whereas fake AV behaves similarly in both environments, because it does not analyze malware in the infected environments. We have investigated three potential indicators, file access pattern, CPU usage, and memory usage, and found that memory usage is an effective indicator to distinguish legitimate AV from fake AV. In an experiment, this indicator identifies all fake AV samples (39 out of 39) as fake and all legitimate AV products (8 out of 8) as legitimate. It is impractical for fake AV to evade this indicator because to do so would require it to detect malware infections, just as legitimate AV does.
- 2014-03-25
著者
-
Kenji Kono
Department of Information and Computer Science, Keio University
-
Kenji Kono
Department Of Information And Computer Science Keio University
-
Masaki Kasuya
Department Of Information And Computer Science Keio University
関連論文
- A Strategy for Efficient Update Propagation on Peer-to-Peer Based Content Distribution Networks
- Using a Virtual Machine Monitor to Slow Down CPU Speed for Embedded Time-Sensitive Software Testing
- VMM-based Detection of Rootkits that Modify File Metadata
- VMM-based Detection of Rootkits that Modify File Metadata
- Strategy for Selecting Replica Server Spots on the Basis of Demand Fluctuations
- Introducing New Resource Management Policies Using a Virtual Machine Monitor
- An Analysis of Fake Antivirus Behaviors
- Using Fault Injection to Analyze the Scope of Error Propagation in Linux
- Screening Legitimate and Fake/Crude Antivirus Software