id: 05820132 dt: a an: 05820132 au: Srivastava, Abhinav; Giffin, Jonathon ti: Automatic discovery of parasitic malware. so: Jha, Somesh (ed.) et al., Recent advances in intrusion detection. 13th international symposium, RAID 2010, Ottawa, Ontario, Canada, September 15‒17, 2010. Proceedings. Berlin: Springer (ISBN 978-3-642-15511-6/pbk). Lecture Notes in Computer Science 6307, 97-117 (2010). py: 2010 pu: Berlin: Springer la: EN cc: ut: ci: li: doi:10.1007/978-3-642-15512-3_6 ab: Summary: Malicious software includes functionality designed to block discovery or analysis by defensive utilities. To prevent correct attribution of undesirable behaviors to the malware, it often subverts the normal execution of benign processes by modifying their in-memory code images to include malicious activity. It is important to find not only maliciously-acting benign processes, but also the actual parasitic malware that may have infected those processes. In this paper, we present techniques for automatic discovery of unknown parasitic malware present on an infected system. We design and develop a hypervisor-based system, Pyrenée, that aggregates and correlates information from sensors at the network level, the network-to-host boundary, and the host level so that we correctly identify the true origin of malicious behavior. We demonstrate the effectiveness of our architecture with security and performance evaluations on a Windows system: we identified all malicious binaries in tests with real malware samples, and the tool imposed overheads of only 0\%-5\% on applications and performance benchmarks. rv: