Martina Lindorfer, Bernhard Miller, M. Neugschwandtner, Christian Platzer
{"title":"Take a bite - Finding the worm in the Apple","authors":"Martina Lindorfer, Bernhard Miller, M. Neugschwandtner, Christian Platzer","doi":"10.1109/ICICS.2013.6782846","DOIUrl":null,"url":null,"abstract":"When it comes to security risks, especially malware, Mac OS X has the questionable reputation of being inherently safe. While there is a substantial body of research and implementations dealing with malware on Windows and, more recently, Android systems, Mac OS X has received little attention so far. To amend this shortcoming, we built a Mac OS X based high-interaction honeypot and used it to evaluate over 6,000 blacklisted URLs to estimate how widespread malware for Mac OS X is today. We further built a dynamic analysis environment and analyzed 148 malicious samples to gain insight into the current state of Mac OS X malware. To the best of our knowledge, we are the first to tackle this task.","PeriodicalId":184544,"journal":{"name":"2013 9th International Conference on Information, Communications & Signal Processing","volume":"12 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2013-12-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"5","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2013 9th International Conference on Information, Communications & Signal Processing","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICICS.2013.6782846","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 5
Abstract
When it comes to security risks, especially malware, Mac OS X has the questionable reputation of being inherently safe. While there is a substantial body of research and implementations dealing with malware on Windows and, more recently, Android systems, Mac OS X has received little attention so far. To amend this shortcoming, we built a Mac OS X based high-interaction honeypot and used it to evaluate over 6,000 blacklisted URLs to estimate how widespread malware for Mac OS X is today. We further built a dynamic analysis environment and analyzed 148 malicious samples to gain insight into the current state of Mac OS X malware. To the best of our knowledge, we are the first to tackle this task.
说到安全风险,尤其是恶意软件,Mac OS X天生安全的名声值得商榷。虽然有大量的研究和实现处理Windows和最近的Android系统上的恶意软件,但到目前为止,Mac OS X几乎没有受到关注。为了弥补这个缺点,我们建立了一个基于Mac OS X的高交互性蜜罐,并使用它来评估超过6000个黑名单url,以估计Mac OS X恶意软件的传播程度。我们进一步构建了一个动态分析环境,分析了148个恶意样本,以了解Mac OS X恶意软件的现状。据我们所知,我们是第一个处理这项任务的国家。