Skip to main navigation Skip to search Skip to main content

MAPMon: A host-based malware detection tool

  • Shih Yao Dai
  • , Sy Yen Kuo*
  • *Corresponding author for this work
  • National Taiwan University
  • National Taiwan University of Science and Technology

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

12 Scopus citations

Abstract

In order for financial-motivated malware programs such as spyware, virus and worm to survive after system rebooted, they have to modify entries in auto start extensibility points (ASEPs), system calls or system files on a comprised system. We call these system resources which a malware program could attack once it intrudes a host as Malware Attacking Points (MAPs). Based on this observation, we design and implement MAPMon, a monitoring mechanism to detect any suspicious change of Malware Attacking Points. This paper describes the design and implementation trade-off of the MAPMon tool. The effectiveness of the MAPMon tool for malware detection is evaluated by using real-world malware programs including those that do not have signatures.

Original languageEnglish
Title of host publicationProceedings - 13th Pacific Rim International Symposium on Dependable Computing, PRDC 2007
Pages346-356
Number of pages11
DOIs
StatePublished - 2007
Externally publishedYes
Event13th Pacific Rim International Symposium on Dependable Computing, PRDC 2007 - Melbourne, VIC, Australia
Duration: 17 12 200719 12 2007

Publication series

NameProceedings - 13th Pacific Rim International Symposium on Dependable Computing, PRDC 2007

Conference

Conference13th Pacific Rim International Symposium on Dependable Computing, PRDC 2007
Country/TerritoryAustralia
CityMelbourne, VIC
Period17/12/0719/12/07

Keywords

  • Auto-start extensibility point
  • Backdoor
  • Honeypot
  • Malicious software
  • Malware attacking points

Fingerprint

Dive into the research topics of 'MAPMon: A host-based malware detection tool'. Together they form a unique fingerprint.

Cite this