Skip to main navigation Skip to search Skip to main content

SpyCon: Emulating user activities to detect evasive spyware

  • SUNY Buffalo

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

14 Scopus citations

Abstract

The success of any spyware is determined by its ability to evade detection. Although traditional detection methodologies employing signature and anomaly based systems have had reasonable success, new class of spyware programs emerge which blend in with user activities to avoid detection. One of the latest antispyware technologies consists of a local agent that generates honeytokens of known parameters (e.g., network access requests) and tricks spyware into assuming it to be legitimate activity. In this paper, as a first step, we address the deficiencies of static honeytoken generation and present an attack that circumvents such detection techniques. We synthesize the attack by means of data mining algorithms like associative rule mining. Next, we present a randomized honeytoken generation mechanism to address this new class of spyware. Experimental results show that (i) static honeytokens are detected with near 100% accuracy, thereby defeating the state-of-the-art anti-spyware technique, (ii) randomized honeytoken generation mechanism is an effective anti-spyware solution.

Original languageEnglish
Title of host publication27th IEEE International Performance Computing and Communications Conference, IPCCC 07
Pages502-509
Number of pages8
DOIs
StatePublished - 2007
Event27th IEEE International Performance Computing and Communications Conference, IPCCC 07 - New Orleans, LA, United States
Duration: Apr 11 2007Apr 13 2007

Publication series

NameConference Proceedings of the IEEE International Performance, Computing, and Communications Conference

Conference

Conference27th IEEE International Performance Computing and Communications Conference, IPCCC 07
Country/TerritoryUnited States
CityNew Orleans, LA
Period04/11/0704/13/07

Keywords

  • Associative rule mining
  • Honeytokens
  • Spyware
  • User activity

Fingerprint

Dive into the research topics of 'SpyCon: Emulating user activities to detect evasive spyware'. Together they form a unique fingerprint.

Cite this