Phantom Malware: Conceal Malicious Actions From Malware Detection Techniques by Imitating User Activity

Autor(en): Witte, Tim Niklas
Stichwörter: BadUSB; Banking; behavior blockers; Computer Science; Computer Science, Information Systems; Engineering; Engineering, Electrical & Electronic; Google; Malware; Microsoft Windows; obfuscation; overlay attacks; Phantoms; ransomware; Telecommunications; Trojan horses; UI redressing; user imitation; User interfaces
Erscheinungsdatum: 2020
Volumen: 8
Startseite: 164428
Seitenende: 164452
State of the art malware detection techniques only consider the interaction of programs with the operating system's API (system calls) for malware classification. This paper demonstrates that techniques like these are insufficient. A point that is overlooked by the currently existing techniques is presented in this paper: Malware is able to interact with windows providing the corresponding functionality in order to execute the desired action by mimicking user activity. In other words, harmful actions will be masked as simulated user actions. To start with, the article introduces User Imitating techniques for concealing malicious commands of the malware as impersonated user activity. Thereafter, the concept of Phantom Malware will be presented: This malware is constantly applying User Imitating to execute each of its malicious actions. A Phantom Ransomware (ransomware employs the User Imitating for every of its malicious actions) is implemented in C++ for testing anti-virus programs in Windows 10. Software of various manufacturers are applied for testing purposes. All of them failed without exception. This paper analyzes the reasons why these products failed and further, presents measures that have been developed against Phantom Malware based on the test results.
ISSN: 21693536
DOI: 10.1109/ACCESS.2020.3021743

Show full item record

Page view(s)

Last Week
Last month
checked on May 21, 2024

Google ScholarTM