Authors
Markus Wagner, Alexander Rind, Niklas Thür, Wolfgang Aigner
Publication date
2017
Journal
Computers & Security
Volume
67
Pages
1–15
Publisher
Elsevier
Description
IT-security experts engage in behavior-based malware analysis in order to learn about previously unknown samples of malicious software (malware) or malware families. For this, they need to find and categorize suspicious patterns from large collections of execution traces. Currently available systems do not meet the analysts' needs which are described as: visual access suitable for complex data structures, visual representations appropriate for IT-security experts, provision of workflow-specific interaction techniques, and the ability to externalize knowledge in the form of rules to ease the analysis process and to share with colleagues. To close this gap, we designed and developed KAMAS, a knowledge-assisted visualization system for behavior-based malware analysis. This paper is a design study that describes the design, implementation, and evaluation of the prototype. We report on the validation of KAMAS with …
Total citations
20172018201920202021202220232024812696711