Extended Abstract: Detecting Scareware by Mining Variable Length Instruction Sequences

نویسندگان

  • Raja Khurram Shahzad
  • Niklas Lavesson
چکیده

Scareware represents scam applications that usually masquerade as security applications such as fake anti-virus software to display fake scanning processes and results to scare users into believing that their systems have been infected with malicious content. Traditional countermeasures that rely on either signature-based methods or heuristic-based methods lack the capability of detecting novel instances of scareware since, for both methods, anti-malware vendors need to catch novel instances, analyze them, create new signatures or rules and then update their databases. Generalizing the scareware detection method so that it can detect novel instances can arguably be regarded as important for user protection. Another problem regarding the detection of scareware is that differences between scareware and legitimate software are subtler than between, say, viruses and legitimate software. That is, there is less information that can be used to distinguish between scareware and legitimate software. To our knowledge, no other studies have been conducted regarding the detection of scareware. There could perhaps be two reasons for this: on the one hand, researchers may have regarded scareware as just another type of malware and thus have assumed that previous malware detectors should work for scareware as well. On the other hand, scareware may have been regarded as harmless. We argue that scareware is too distinct to other forms of malware for previous detectors to work and that the risks of scareware could be substantial primarily due to the fact that scareware uses social engineering to gain access to the complete file system of personal computers.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Detecting Internet Worms Using Data Mining Techniques

Internet worms pose a serious threat to computer security. Traditional approaches using signatures to detect worms pose little danger to the zero day attacks. The focus of malware research is shifting from using signature patterns to identifying the malicious behavior displayed by the malwares. This paper presents a novel idea of extracting variable length instruction sequences that can identif...

متن کامل

Detecting Trojans Using Data Mining Techniques

A trojan horse is a program that surreptitiously performs its operation under the guise of a legitimate program. Traditional approaches using signatures to detect these programs pose little danger to new and unseen samples whose signatures are not available. The focus of malware research is shifting from using signature patterns to identifying the malicious behavior displayed by these malwares....

متن کامل

Efficient Detection of Internet Worms Using Data Mining Techniques

Internet worms pose a serious threat to computer security.Traditional approaches using signatures to detect worms pose little danger to the zero day attacks. The focus of malware research is shifting from using signature patterns to identifying the malicious behavior displayed by the malwaresThis paper presents a novel idea of extracting variable length instruction sequences that can identify w...

متن کامل

The Effect of Explicit Instruction of Formulaic Sequences on Oral Proficiency Improvement of Young Iranian EFL Students

Abstract This study aimed to shed light on young Iranian EFL students’ oral proficiency improvement through explicit instruction of formulaic sequences (FSs). This pretest-posttest quasi experimental study was conducted in a bilingual school in Shahrekord, Iran. Accordingly, based on ACTFL OPI test, two groups of low intermediate students with age range of 11 to 12 were chosen to be assigned as...

متن کامل

The Effect of Explicit Instruction of Formulaic Sequences on Oral Proficiency Improvement of Young Iranian EFL Students

Abstract This study aimed to shed light on young Iranian EFL students’ oral proficiency improvement through explicit instruction of formulaic sequences (FSs). This pretest-posttest quasi experimental study was conducted in a bilingual school in Shahrekord, Iran. Accordingly, based on ACTFL OPI test, two groups of low intermediate students with age range of 11 to 12 were chosen to be assigned as...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2011