Automated spyware collection and analysis

Stamminger, Andreas;Kruegel, Christopher; Vigna, Giovanni; Kirda, Engin
ISC 2009, Information Security Conference, September 7-9, 2009, Pisa, Italy / Also published in LNCS, Volume 5735/2009, ISBN: 978-3-642-04473-1

Various online studies on the prevalence of spyware attest overwhelming numbers (up to 80%) of infected home computers. However, the term spyware is ambiguous and can refer to anything from plug-ins that display advertisements to software that records and leaks user input. To shed light on the true nature of the spyware problem, a recent measurement paper attempted to quantify the extent of spyware on the Internet. More precisely, the authors crawled the web and analyzed the executables that were downloaded. For this analysis, only a single anti-spyware tool was used. Unfortunately, this is a major shortcoming as the results from this single tool neither capture the actual amount of the threat, nor appropriately classify the functionality of suspicious executables in many cases. For our analysis, we developed a fully-automated infrastructure to collect and install executables from the web. We use three different techniques to analyze these programs: an online database of spyware-related identi- fiers, signature-based scanners, and a behavior-based malware detection technique. We present the results of a measurement study that lasted about ten months. During this time, we crawled over 15 million URLs and downloaded 35,853 executables. Almost half of the spyware samples we found were not recognized by the tool used in previous work. Moreover, a significant fraction of the analyzed programs (more than 80%) was incorrectly classified. This underlines that our measurement results are more comprehensive and precise than those of previous approaches, allowing us to draw a more accurate picture of the spyware threat.


DOI
Type:
Conference
City:
Pisa
Date:
2009-09-07
Department:
Digital Security
Eurecom Ref:
2865
Copyright:
© Springer. Personal use of this material is permitted. The definitive version of this paper was published in ISC 2009, Information Security Conference, September 7-9, 2009, Pisa, Italy / Also published in LNCS, Volume 5735/2009, ISBN: 978-3-642-04473-1 and is available at : http://dx.doi.org/10.1007/978-3-642-04474-8_17

PERMALINK : https://www.eurecom.fr/publication/2865