Phantom Malware: Conceal Malicious Actions From Malware Detection Techniques by Imitating User Activity

Bitte benutzen Sie diese Kennung, um auf die Ressource zu verweisen:
https://osnadocs.ub.uni-osnabrueck.de/handle/urn:nbn:de:gbv:700-202105114440
Open Access logo originally created by the Public Library of Science (PLoS)
Titel: Phantom Malware: Conceal Malicious Actions From Malware Detection Techniques by Imitating User Activity
Autor(en): Witte, Tim Niklas
ORCID des Autors: https://orcid.org/0000-0002-8727-9483
Zusammenfassung: State of the art malware detection techniques only consider the interaction of programs with the operating system's API (system calls) for malware classification. This paper demonstrates that techniques like these are insufficient. A point that is overlooked by the currently existing techniques is presented in this paper: Malware is able to interact with windows providing the corresponding functionality in order to execute the desired action by mimicking user activity. In other words, harmful actions will be masked as simulated user actions. To start with, the article introduces User Imitating techniques for concealing malicious commands of the malware as impersonated user activity. Thereafter, the concept of Phantom Malware will be presented: This malware is constantly applying User Imitating to execute each of its malicious actions. A Phantom Ransomware (ransomware employs the User Imitating for every of its malicious actions) is implemented in C++ for testing anti-virus programs in Windows 10. Software of various manufacturers are applied for testing purposes. All of them failed without exception. This paper analyzes the reasons why these products failed and further, presents measures that have been developed against Phantom Malware based on the test results.
Bibliografische Angaben: T. N. Witte, "Phantom Malware: Conceal Malicious Actions From Malware Detection Techniques by Imitating User Activity," in IEEE Access, vol. 8, pp. 164428-164452, 2020
URL: https://osnadocs.ub.uni-osnabrueck.de/handle/urn:nbn:de:gbv:700-202105114440
Schlagworte: Malware; ransomware; user imitation; UI redressing; overlay attacks; BadUSB; obfuscation; behavior blockers
Erscheinungsdatum: 4-Sep-2020
Lizenzbezeichnung: Attribution 4.0 International
URL der Lizenz: http://creativecommons.org/licenses/by/4.0/
Publikationstyp: Einzelbeitrag in einer wissenschaftlichen Zeitschrift [article]
Enthalten in den Sammlungen:FB06 - Hochschulschriften
Open-Access-Publikationsfonds

Dateien zu dieser Ressource:
Datei Beschreibung GrößeFormat 
IEEEAccess_Witte_2020.pdf1,86 MBAdobe PDF
IEEEAccess_Witte_2020.pdf
Miniaturbild
Öffnen/Anzeigen


Diese Ressource wurde unter folgender Copyright-Bestimmung veröffentlicht: Lizenz von Creative Commons Creative Commons