Large Scale Studies: Malware Needles in a Haystack

  • Giovanni Bertão
  • Marcus Botacin
  • André Grégio
  • Paulo Lício de Geus

Resumo


Malware overview reports are valuable information to understand threats behavior and develop proper countermeasures. Currently, most of these studies are focused on either fine-grained, individual sample analysis or coarsegrained landscapes. On the one hand, only the first allows professionals to handle specific security breaches. On the other hand, only the second allows understanding threat scenario as a whole. We claim a complete security treatment is only possible when combining both approaches. Therefore, in this work, we present an analysis of a large malware dataset, showing the distinctions between coarse-grained and fine-grained analysis results. We present both a general threat scenario based on coarse-grained results as well as we detail our fine-grained results to identify particular malicious constructions to antecipate incident response of future threats.
Publicado
25/10/2018
Como Citar

Selecione um Formato
BERTÃO, Giovanni; BOTACIN, Marcus; GRÉGIO, André; GEUS, Paulo Lício de. Large Scale Studies: Malware Needles in a Haystack. In: WORKSHOP DE TRABALHOS DE INICIAÇÃO CIENTÍFICA E DE GRADUAÇÃO - SIMPÓSIO BRASILEIRO DE SEGURANÇA DA INFORMAÇÃO E DE SISTEMAS COMPUTACIONAIS (SBSEG), 18. , 2018, Natal. Anais [...]. Porto Alegre: Sociedade Brasileira de Computação, 2018 . p. 203 - 212.