Skip to main navigation Skip to search Skip to main content

Toward Automatically Generating User-Specific Recovery Procedures after Windows Malware Infections

Research output: Chapter in Book/Report/Conference proceedingConference contributionAcademicpeer-review

57 Downloads (Pure)

Abstract

Despite significant advancements in proactive malware detection and prevention, complete prevention of malware infiltration remains unattainable. Once malware is present on a system, it can make persistent changes that affect its stability, making user-specific recovery post-infection an important problem to address. Current solutions involve extensive monitoring to precisely pinpoint the changes that malware has made, which are impractical for home environments due to their high resource demands. This paper introduces a prototype for automatically generating userspecific malware recovery procedures that fully operates post-mortem. By leveraging forensic data collected on Windows by default, we replicate the original conditions under which the malware executed in a sandbox and automatically infer the exact system resources that the malware changed without imposing additional performance burdens on the user's machine. We test a prototype against 894 realworld malware samples and three real-world, environment-sensitive malware campaigns, and achieve a full recovery rate of 51.3 % even with no additional monitoring enabled. We conclude by sharing insights on the importance of machine replication and sandbox configurability in future malware research.

Original languageEnglish
Title of host publicationProceedings - 10th IEEE European Symposium on Security and Privacy Workshops, Euro S and PW 2025
PublisherIEEE
Pages39-47
Number of pages9
ISBN (Electronic)9798331595463
DOIs
Publication statusPublished - 2025
Event10th IEEE European Symposium on Security and Privacy, Euro S&PW 2025 - Venice, Italy
Duration: 30 Jun 20254 Jul 2025
Conference number: 10

Conference

Conference10th IEEE European Symposium on Security and Privacy, Euro S&PW 2025
Abbreviated titleEuro S&P 2025
Country/TerritoryItaly
CityVenice
Period30/06/254/07/25

Keywords

  • Malicious Behaviors
  • Malware
  • Recovery

Fingerprint

Dive into the research topics of 'Toward Automatically Generating User-Specific Recovery Procedures after Windows Malware Infections'. Together they form a unique fingerprint.

Cite this