A Comprehensive Analysis of Today's Malware and Its Distribution Network: Common Adversary Strategies and Implications

Cited 1 time in webofscience Cited 0 time in scopus
  • Hit : 320
  • Download : 0
Malware has plagued the internet and computing systems for decades. The war against malware has always been an arms race. Researchers and industry have constantly improved detection and prevention methodologies against increasingly more evasive malware. Keeping up with the constantly changing adversary tactics for evading defensive efforts and maintaining an efficient malware supply chain is imperative to stay ahead in the competition. In this paper, we present a large-scale and comprehensive analysis of the current state of malware distribution. For the analysis, we accumulated a dataset that contains 99,312 malware binary samples from 38,659 malware distribution sites over 287 days. Using our dataset, we perform a comprehensive analysis of the collected malware binaries and URLs to provide up-to-date statistics and insights into the adversary strategies. We analyze both malware distribution sites and malware binaries collected from them. Regarding binary analysis, we perform a multifaceted analysis on the characteristics on the collected binaries, including malware family label classification and file similarity-based clustering. With distribution site analysis, we analyze the IP addresses, domains, AS registration distribution and URL lexical distribution of malware distribution sites. We further discuss the statistical relationship between malware families and their distribution domains. Most importantly, we discuss the current trends in malware distribution today and reveal adversary strategies through our extensive amount of analysis results. Then, we suggest future directions for fight against malware distribution.
Publisher
IEEE-INST ELECTRICAL ELECTRONICS ENGINEERS INC
Issue Date
2022
Language
English
Article Type
Article
Citation

IEEE ACCESS, v.10, pp.49566 - 49584

ISSN
2169-3536
DOI
10.1109/ACCESS.2022.3171226
URI
http://hdl.handle.net/10203/296728
Appears in Collection
EE-Journal Papers(저널논문)
Files in This Item
There are no files associated with this item.
This item is cited by other documents in WoS
⊙ Detail Information in WoSⓡ Click to see webofscience_button
⊙ Cited 1 items in WoS Click to see citing articles in records_button

qr_code

  • mendeley

    citeulike


rss_1.0 rss_2.0 atom_1.0