skip to main content
10.1145/3065913.3065921acmconferencesArticle/Chapter ViewAbstractPublication PageseurosysConference Proceedingsconference-collections
research-article

Looking Back on Three Years of Flash-based Malware

Published:23 April 2017Publication History

ABSTRACT

Adobe Flash is about to be replaced by alternative technologies, yet Flash-based malware appears to be more common then ever. In this paper we inspect the properties and temporal distribution of this class of malware over a period of three consecutive years and 2.3 million unique Flash animations. In particular, we focus on initially undetected malware and thus look at a subset for which traditional methods have failed to provide timely detection. We analyze the prevalence of these samples and characterize their nature.

References

  1. Adobe Systems. Flash, HTML5 and open web standards. https://blogs.adobe.com/conversations/2015/11/flash-html5-and-open-web-standards.html, visited March 2017.Google ScholarGoogle Scholar
  2. Adobe Systems. Adobe Flash runtimes: Statistics. http://www.adobe.com/products/flashruntimes/statistics.html, visited March 2017.Google ScholarGoogle Scholar
  3. D. Caselden, C. Souffrant, and G. Jiang. Flash in 2015. https://www.fireeye.com/blog/threat-research/2015/03/flash_in_2015.html, visited March 2017.Google ScholarGoogle Scholar
  4. S. Ford, M. Cova, C. Kruegel, and G. Vigna. Analyzing and detecting malicious flash advertisements. In Proc. of Annual Computer Security Applications Conference (ACSAC), 2009. Google ScholarGoogle ScholarDigital LibraryDigital Library
  5. T. Hirvonen. Dynamic instrumentation tool for adobe flash player built on intel pin. https://github.com/F-Secure/Sulo, visited March 2017.Google ScholarGoogle Scholar
  6. HTTP Archive. http://www.httparchive.org.Google ScholarGoogle Scholar
  7. M. Hurier, K. Allix, T. F. Bissyandé, J. Klein, and Y. L. Traon. On the lack of consensus in anti-virus decisions: Metrics and insights on building ground truths of android malware. In Proc. of Detection of Intrusions and Malware & Vulnerability Assessment (DIMVA), 2016.Google ScholarGoogle ScholarDigital LibraryDigital Library
  8. A. Kantchelian, M. C. Tschantz, S. Afroz, B. Miller, V. Shankar, R. Bachwani, A. D. Joseph, and J. D. Tygar. Better malware ground truth: Techniques for weighting anti-virus vendor labels. In Proc. of ACM Workshop on Artificial Intelligence and Security (AISEC), 2015. Google ScholarGoogle ScholarDigital LibraryDigital Library
  9. KINDI Software. secureSWF: Protect, encrypt, and optimize swf flash. http://www.kindi.com, visited March 2017.Google ScholarGoogle Scholar
  10. A. LaForge. Flash and chrome. https://blog.google/products/chrome/flash-and-chrome, visited March 2017.Google ScholarGoogle Scholar
  11. Z. Li, K. Zhang, Y. Xie, F. You, and X. Wang. Knowing your enemy: Understanding and detecting malicious web advertising. In Proc. of ACM Conference on Computer and Communications Security (CCS), 2012. Google ScholarGoogle ScholarDigital LibraryDigital Library
  12. F. Lindner. Preventing Adobe Flash exploitation - Blitzableiter - a signature-less protection tool. In Proc. of Black Hat USA, 2010.Google ScholarGoogle Scholar
  13. C. Linn and S. Debray. Obfuscation of executable code to improve resistance to static disassembly. In Proc. of ACM Conference on Computer and Communications Security (CCS), 2003. Google ScholarGoogle ScholarDigital LibraryDigital Library
  14. F. Maggi, A. Bellini, G. Salvaneschi, and S. Zanero. Finding non-trivial malware naming inconsistencies. In Proc. of International Conference on Information Systems Security (ICISS), 2011. Google ScholarGoogle ScholarDigital LibraryDigital Library
  15. B. Miller, A. Kantchelian, M. C. Tschantz, S. Afroz, R. Bachwani, R. Faizullabhoy, L. Huang, V. Shankar, T. Wu, G. Yiu, A. D. Joseph, and J. D. Tygar. Reviewer integration and performance measurement for malware detection. In Proc. of Detection of Intrusions and Malware & Vulnerability Assessment (DIMVA), 2016. Google ScholarGoogle ScholarDigital LibraryDigital Library
  16. A. Mohaisen and O. Alrawi. AV-Meter: an evaluation of antivirus scans and labels. In Proc. of Detection of Intrusions and Malware & Vulnerability Assessment (DIMVA), 2014.Google ScholarGoogle ScholarCross RefCross Ref
  17. S. Özkan. CVE Details. http://www.cvedetails.com, visited March 2017.Google ScholarGoogle Scholar
  18. M. Sebastián, R. Rivera, P. Kotzias, and J. Caballero. AVclass: A tool for massive malware labeling. In Proc. of International Symposium on Research in Attacks, Intrusions and Defenses (RAID), 2016. Google ScholarGoogle ScholarCross RefCross Ref
  19. SWFLock.com. SWFLock: Online encryption software for flash. http://www.swflock.com, visited March 2017.Google ScholarGoogle Scholar
  20. Trustwave Holdings, Inc. Trustwave global security report. Technical report, Trustwave Holdings, Inc., 2016.Google ScholarGoogle Scholar
  21. T. van Overveldt, C. Kruegel, and G. Vigna. FlashDetect: ActionScript 3 malware detection. In Proc. of International Symposium on Research in Attacks, Intrusions and Defenses (RAID), 2012. Google ScholarGoogle ScholarDigital LibraryDigital Library
  22. C. Wressnegger, F. Yamaguchi, D. Arp, and K. Rieck. Comprehensive analysis and detection of flash-based malware. In Proc. of Conference on Detection of Intrusions and Malware & Vulnerability Assessment (DIMVA), 2016. Google ScholarGoogle ScholarDigital LibraryDigital Library
  23. Yushi High Technology Ltd. DoSWF -- professional flash swf encryptor. http://doswf.org, visited March 2017.Google ScholarGoogle Scholar
  24. V. Zakorzhevsky. New Flash Player 0-day (CVE-2014-0515) Used in Watering-hole Attacks. https://securelist.com/blog/incidents/59399/new-flash-player-0-daycve-2014-0515-used-in-watering-hole-attacks/, visited March 2017.Google ScholarGoogle Scholar
  1. Looking Back on Three Years of Flash-based Malware

      Recommendations

      Comments

      Login options

      Check if you have access through your login credentials or your institution to get full access on this article.

      Sign in
      • Published in

        cover image ACM Conferences
        EuroSec'17: Proceedings of the 10th European Workshop on Systems Security
        April 2017
        65 pages
        ISBN:9781450349352
        DOI:10.1145/3065913

        Copyright © 2017 ACM

        Permission to make digital or hard copies of all or part of this work for personal or classroom use is granted without fee provided that copies are not made or distributed for profit or commercial advantage and that copies bear this notice and the full citation on the first page. Copyrights for components of this work owned by others than the author(s) must be honored. Abstracting with credit is permitted. To copy otherwise, or republish, to post on servers or to redistribute to lists, requires prior specific permission and/or a fee. Request permissions from [email protected].

        Publisher

        Association for Computing Machinery

        New York, NY, United States

        Publication History

        • Published: 23 April 2017

        Permissions

        Request permissions about this article.

        Request Permissions

        Check for updates

        Qualifiers

        • research-article
        • Research
        • Refereed limited

        Acceptance Rates

        EuroSec'17 Paper Acceptance Rate10of24submissions,42%Overall Acceptance Rate47of113submissions,42%

        Upcoming Conference

        EuroSys '24
        Nineteenth European Conference on Computer Systems
        April 22 - 25, 2024
        Athens , Greece

      PDF Format

      View or Download as a PDF file.

      PDF

      eReader

      View online with eReader.

      eReader