scispace - formally typeset
K

Kirat Dhilung Hang

Researcher at IBM

Publications -  27
Citations -  670

Kirat Dhilung Hang is an academic researcher from IBM. The author has contributed to research in topics: Malware & Malware analysis. The author has an hindex of 10, co-authored 27 publications receiving 588 citations. Previous affiliations of Kirat Dhilung Hang include University of California, Santa Barbara.

Papers
More filters
Proceedings Article

Barecloud: bare-metal analysis-based evasive malware detection

TL;DR: BareCloud is presented, an automated evasive malware detection system based on bare-metal dynamic malware analysis, which introduces a novel approach of hierarchical similarity-based malware behavior comparison to analyze the behavior of a sample in the various analysis systems.
Proceedings ArticleDOI

MalGene: Automatic Extraction of Malware Analysis Evasion Signature

TL;DR: MalGene is presented, an automated technique for extracting analysis evasion signatures that leverages algorithms borrowed from bioinformatics to automatically locate evasive behavior in system call sequences and constructs a succinct evasion signature, which can be used by an analyst to quickly understand evasions.
Proceedings ArticleDOI

BareBox: efficient malware analysis on bare-metal

TL;DR: This paper presents the design, implementation, and evaluation of a malware analysis framework for bare-metal systems that is based on a fast and rebootless system restore technique, which was able to perform a rebootless restore of a live Windows system within four seconds.
Journal Article

Ten Years of iCTF: The Good, The Bad, and The Ugly

TL;DR: This paper presents a framework that is based on the lessons learned in running, for more than 10 years, the largest educational CTF in the world, called iCTF, to provide educational institutions and other organizations with the ability to run customizable CTF competitions.
Proceedings ArticleDOI

BareDroid: Large-Scale Analysis of Android Apps on Real Devices

TL;DR: BareDroid is proposed, a system that makes bare-metal analysis of Android apps feasible by quickly restoring real devices to a clean snapshot and is released as an open source project in the hope it can be useful to other researchers to strengthen their analysis systems.