Skip to main content

AGIS: Towards automatic generation of infection signatures

Publication ,  Conference
Li, Z; Wang, XF; Liang, Z; Reiter, MK
Published in: Proceedings of the International Conference on Dependable Systems and Networks
October 13, 2008

An important yet largely uncharted problem in malware defense is how to automate generation of infection signatures for detecting compromised systems, i.e., signatures that characterize the behavior of malware residing on a system. To this end, we develop AGIS, a host-based technique that detects infections by malware and automatically generates an infection signature of the malware. AGIS monitors the runtime behavior of suspicious code according to a set of security policies to detect an infection, and then identifies its characteristic behavior in terms of system or API calls. AGIS then statically analyzes the corresponding executables to extract the instructions important to the infection's mission. These instructions can be used to build a template for a static-analysis-based scanner, or a regular-expression signature for legacy scanners. AGIS also detects encrypted malware and generates a signature from its plaintext decryption loop. We implemented AGIS on Windows XP and evaluated it against real-life malware, including keyloggers, mass-mailing worms, and a well-known mutation engine. The experimental results demonstrate the effectiveness of our technique in detecting new infections and generating high-quality signatures. © 2008 IEEE.

Duke Scholars

Altmetric Attention Stats
Dimensions Citation Stats

Published In

Proceedings of the International Conference on Dependable Systems and Networks

DOI

Publication Date

October 13, 2008

Start / End Page

237 / 246
 

Citation

APA
Chicago
ICMJE
MLA
NLM
Li, Z., Wang, X. F., Liang, Z., & Reiter, M. K. (2008). AGIS: Towards automatic generation of infection signatures. In Proceedings of the International Conference on Dependable Systems and Networks (pp. 237–246). https://doi.org/10.1109/DSN.2008.4630092
Li, Z., X. F. Wang, Z. Liang, and M. K. Reiter. “AGIS: Towards automatic generation of infection signatures.” In Proceedings of the International Conference on Dependable Systems and Networks, 237–46, 2008. https://doi.org/10.1109/DSN.2008.4630092.
Li Z, Wang XF, Liang Z, Reiter MK. AGIS: Towards automatic generation of infection signatures. In: Proceedings of the International Conference on Dependable Systems and Networks. 2008. p. 237–46.
Li, Z., et al. “AGIS: Towards automatic generation of infection signatures.” Proceedings of the International Conference on Dependable Systems and Networks, 2008, pp. 237–46. Scopus, doi:10.1109/DSN.2008.4630092.
Li Z, Wang XF, Liang Z, Reiter MK. AGIS: Towards automatic generation of infection signatures. Proceedings of the International Conference on Dependable Systems and Networks. 2008. p. 237–246.

Published In

Proceedings of the International Conference on Dependable Systems and Networks

DOI

Publication Date

October 13, 2008

Start / End Page

237 / 246