SigIL: A Signature-Based Approach of Malware Detection on Intermediate Language

Abstract

The Internet of Things (IoT) has brought about significant advancements in connectivity but has also introduced security challenges due to the diverse range of IoT devices. Traditional security solutions struggle to detect malware specifically designed for IoT devices. To address this, there is a need for cross-device malware detection systems that can transcend device differences. Signature scanning is a widely used technique to detect malware, but it has limitations when dealing with binaries compiled for different architectures. This paper proposes SigIL (Signature scanning on Intermediate Language), a tool that identifies significant patterns in binary programs using their intermediate representation. By shifting the focus to intermediate languages instead of byte sequences, SigIL aims to make signatures independent of architectural details, allowing the use of a single signature to identify multiple binaries obtained by compiling the same source code for different architectures.

Publication
Computer Security. ESORICS 2023 International Workshops