Skip to main navigation Skip to search Skip to main content

Behavioral detection of malware: From a survey towards an established taxonomy

  • Orange Labs
  • French Army Signals Academy

Research output: Contribution to journalArticlepeer-review

Abstract

Behavioral detection differs from appearance detection in that it identifies the actions performed by the malware rather than syntactic markers. Identifying these malicious actions and interpreting their final purpose is a complex reasoning process. This paper draws up a survey of the different reasoning techniques deployed among the behavioral detectors. These detectors have been classified according to a new taxonomy introduced inside the paper. Strongly inspired from the domain of program testing, this taxonomy divides the behavioral detectors into two main families: simulation-based and formal detectors. Inside these families, ramifications are then derived according to the data collection mechanisms the data interpretation, the adopted model and its generation, and the decision support.

Original languageEnglish
Pages (from-to)251-266
Number of pages16
JournalJournal in Computer Virology
Volume4
Issue number3
DOIs
Publication statusPublished - 1 Aug 2008
Externally publishedYes

Fingerprint

Dive into the research topics of 'Behavioral detection of malware: From a survey towards an established taxonomy'. Together they form a unique fingerprint.

Cite this