Phantom Malware: Conceal Malicious Actions From Malware Detection Techniques by Imitating User Activity

Please use this identifier to cite or link to this item:
https://osnadocs.ub.uni-osnabrueck.de/handle/urn:nbn:de:gbv:700-202105114440
Open Access logo originally created by the Public Library of Science (PLoS)
Title: Phantom Malware: Conceal Malicious Actions From Malware Detection Techniques by Imitating User Activity
Authors: Witte, Tim Niklas
ORCID of the author: https://orcid.org/0000-0002-8727-9483
Abstract: State of the art malware detection techniques only consider the interaction of programs with the operating system's API (system calls) for malware classification. This paper demonstrates that techniques like these are insufficient. A point that is overlooked by the currently existing techniques is presented in this paper: Malware is able to interact with windows providing the corresponding functionality in order to execute the desired action by mimicking user activity. In other words, harmful actions will be masked as simulated user actions. To start with, the article introduces User Imitating techniques for concealing malicious commands of the malware as impersonated user activity. Thereafter, the concept of Phantom Malware will be presented: This malware is constantly applying User Imitating to execute each of its malicious actions. A Phantom Ransomware (ransomware employs the User Imitating for every of its malicious actions) is implemented in C++ for testing anti-virus programs in Windows 10. Software of various manufacturers are applied for testing purposes. All of them failed without exception. This paper analyzes the reasons why these products failed and further, presents measures that have been developed against Phantom Malware based on the test results.
Citations: T. N. Witte, "Phantom Malware: Conceal Malicious Actions From Malware Detection Techniques by Imitating User Activity," in IEEE Access, vol. 8, pp. 164428-164452, 2020
URL: https://osnadocs.ub.uni-osnabrueck.de/handle/urn:nbn:de:gbv:700-202105114440
Subject Keywords: Malware; ransomware; user imitation; UI redressing; overlay attacks; BadUSB; obfuscation; behavior blockers
Issue Date: 4-Sep-2020
License name: Attribution 4.0 International
License url: http://creativecommons.org/licenses/by/4.0/
Type of publication: Einzelbeitrag in einer wissenschaftlichen Zeitschrift [article]
Appears in Collections:FB06 - Hochschulschriften
Open-Access-Publikationsfonds

Files in This Item:
File Description SizeFormat 
IEEEAccess_Witte_2020.pdf1,86 MBAdobe PDF
IEEEAccess_Witte_2020.pdf
Thumbnail
View/Open


This item is licensed under a Creative Commons License Creative Commons