Title
Using verification technology to specify and detect malware
Abstract
Computer viruses and worms are major threats for our computer infrastructure, and thus, for economy and society at large. Recent work has demonstrated that a model checking based approach to malware detection can capture the semantics of security exploits more accurately than traditional approaches, and consequently achieve higher detection rates. In this approach, malicious behavior is formalized using the expressive specification language CTPL based on classic CTL. This paper gives an overview of our toolchain for malware detection and presents our new system for computer assisted generation of malicious code specifications.
Year
DOI
Venue
2007
10.1007/978-3-540-75867-9_63
EUROCAST
Keywords
Field
DocType
traditional approach,malicious behavior,malware detection,expressive specification language,major threat,computer infrastructure,classic ctl,malicious code specification,verification technology,higher detection rate,computer virus,computer viruses,model checking
Specification language,Kripke structure,Cryptovirology,Model checking,Computer security,Computer science,Computer virus,Exploit,Malware,Toolchain
Conference
Volume
ISSN
ISBN
4739
0302-9743
3-540-75866-6
Citations 
PageRank 
References 
13
0.68
7
Authors
3
Name
Order
Citations
PageRank
Andreas Holzer119713.62
Johannes Kinder246423.49
Helmut Veith32476140.58