Dongyan Xu, OS-Level Taint Analysis for Malware Investigation and Defense episode artwork

EPISODE · Nov 29, 2006 · 57 MIN

Dongyan Xu, OS-Level Taint Analysis for Malware Investigation and Defense

from CERIAS Weekly Security Seminar - Purdue University

The Internet is facing threats from increasingly stealthy andsophisticated malware. Recent reports have suggested that newcomputer worms and malware deliberately avoid fast massivepropagation. Instead, they lurk in infected machines and inflictcontaminations over time, such as rootkit and backdoorinstallation, botnet creation, and data/identity theft. In defenseagainst Internet malware, the following tasks are critical: (1)raising timely alerts to trigger a malware investigation, (2)determining the break-in point of malware, i.e. the vulnerablesoftware via which the malware initially infiltrates the victim,and (3) identifying all contaminations inflicted by the malwareduring its residence in the victim. In this talk, I will presentProcess Coloring, an information flow-preserving, provenance-awareapproach to malware investigation. In particular, I willdemonstrate that through the preservation and tainting of malwarebreak-in provenance along OS-level information flows, malwareinvestigators will be able to improve the efficiency andeffectiveness of existing log-based intrusion investigation tools.Furthermore, process coloring brings the new capability of runtimemalware alert, which cannot be achieved by existing log-basedtools. I will also present results of our experiments with anumber of real-world Internet worms as well as a highlytamper-resistant implementation of process coloring usingvirtualization-based techniques. About the speaker: Dongyan Xu is an assistant professor of computer science at PurdueUniversity. He received his Ph.D. in computer science from theUniversity of Illinois at Urbana-Champaign in 2001. His currentresearch focuses on virtualization technologies and theirapplications to malware defense on the Internet and virtualdistributed computing in the cyberinfrastructure.

Episode metadata supplied by the publisher feed · Published Nov 29, 2006

Embed this episode

NOW PLAYING

Dongyan Xu, OS-Level Taint Analysis for Malware Investigation and Defense

0:00 57:40

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

Frequently Asked Questions

How long is this episode of CERIAS Weekly Security Seminar - Purdue University?

This episode is 57 minutes long.

When was this CERIAS Weekly Security Seminar - Purdue University episode published?

This episode was published on November 29, 2006.

Can I download this CERIAS Weekly Security Seminar - Purdue University episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!