Automatic Generation of MAEC and STIX Standards for Android Malware Threat Intelligence

  • Park, Jungsoo
  • Vu, Long Nguyen
  • Bencivengo, George
  • Jung, Souhwan
Citations

WEB OF SCIENCE

3
Citations

SCOPUS

5

초록

Due to the increasing number of malicious software (also known as malware), methods for sharing threat information are being studied by various organizations. The Malware Attribute Enumeration and Characterization (MAEC) format of malware is created by analysts, converted to Structured Threat Information Expression (STIX), and distributed by using Trusted Automated eXchange of Indicator Information (TAXII) protocol. Currently, when sharing malware analysis results, analysts have to manually input them into MAEC. Not many analysis results are shared publicly. In this paper, we propose an automated MAEC conversion technique for sharing analysis results of malicious Android applications. Upon continuous research and study of various static and dynamic analysis techniques of Android Applications, we developed a conversion tool by classifying parts that can be converted automatically through MAEC standard analysis, and parts that can be entered manually by analysts. Also using MAEC-to-STIX conversion, we have discovered that the MAEC file can be converted into STIX. Although other researches have been conducted on automatic conversion techniques of MAEC, they were limited to Windows and Linux only. In further verification of the conversion rate, we confirmed that analysts could improve the efficiency of analysis and establish a faster sharing system to cope with various Android malware using our proposed technique.

키워드

MAECSTIXAndroid MalwareCyber Threat Intelligence
제목
Automatic Generation of MAEC and STIX Standards for Android Malware Threat Intelligence
저자
Park, JungsooVu, Long NguyenBencivengo, GeorgeJung, Souhwan
DOI
10.3837/tiis.2020.08.015
발행일
2020-08
유형
Article
저널명
KSII Transactions on Internet and Information Systems
14
8
페이지
3420 ~ 3436