Formal Methods for Malware Detection

Award Information
Agency: Department of Defense
Branch: Air Force
Contract: FA8750-06-C-0159
Agency Tracking Number: O053-SP2-1241
Amount: $100,000.00
Phase: Phase I
Program: SBIR
Awards Year: 2006
Solicitation Year: 2005
Solicitation Topic Code: OSD05-SP2
Solicitation Number: 2005.3
Small Business Information
30 River Court, Suite 2301, Jersey City, NJ, 07310
DUNS: 361627933
HUBZone Owned: N
Woman Owned: N
Socially and Economically Disadvantaged: Y
Principal Investigator
 Miroslav Velev
 President, CEO, CTO
 (201) 626-3192
Business Contact
 Miroslav Velev
Title: President, CEO, CTO
Phone: (201) 626-3192
Research Institution
Our objective is to develop highly automatic and scalable formal methods for malware detection. Existing tools for malware detection operate by searching for pattern matches with respect to signatures of known malware, and can account for only limited variations in the malware. That makes these detectors generally incapable of identifying newly released malware. Furthermore, due to the short signatures used for most malware, and the inability of these detectors to account for many code obfuscations, i.e., code transformations that preserve the malicious behavior and produce code with a radically different structure, such malware detectors are virtually incapable of identifying most of the obfuscated variants of known malware. In this proposed research we will: 1) investigate formal methods for detection of malicious intent in binary code; 2) develop automatic formal techniques to detect obfuscations that are based on reordering of the memory accesses in known malware; 3) explore formal approaches to account for obfuscations that are based on replacing instructions with different instructions that have equivalent semantics; and 4) develop efficient translations to SAT of the Boolean formulas generated in formal detection of malware in order to enable our malware detection tool to run on commodity PCs with limited memory.

* Information listed above is at the time of submission. *

Agency Micro-sites

SBA logo
Department of Agriculture logo
Department of Commerce logo
Department of Defense logo
Department of Education logo
Department of Energy logo
Department of Health and Human Services logo
Department of Homeland Security logo
Department of Transportation logo
Environmental Protection Agency logo
National Aeronautics and Space Administration logo
National Science Foundation logo
US Flag An Official Website of the United States Government