AutoMal: automatic clustering and signature generation for malwares based on the network flow

被引:1
|
作者
Hao, Sun [1 ,2 ]
Wang, Wen [1 ]
Lu, Huabiao [1 ]
Ren, Peige [1 ]
机构
[1] Natl Univ Def Technol, Sch Comp, Changsha, Hunan, Peoples R China
[2] Natl Univ Def Technol, Natl Key Lab Parallel & Distributed Proc, Changsha, Hunan, Peoples R China
基金
美国国家科学基金会; 国家高技术研究发展计划(863计划);
关键词
network malware; clustering; signature generation; matrix; feature hashing;
D O I
10.1002/sec.1029
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The volume of malwares is growing at an exponential speed nowadays. This huge growth makes it extremely hard to analyse malware manually. Most existing signatures extracting methods are based on string signatures, and string matching is not accurate and time consuming. Therefore, this paper presents AutoMal, a system for automatically extracting signatures from large-scale malwares. Firstly, the system proposes to represent the network flows by using feature hashing, which can dramatically reduce the high-dimensional feature spaces that are general in malware analysis. Then, we design a clustering and median filtering method to classify the malware vectors into different types. Finally, it introduces the signature generation algorithm based on Bayesian method. The system can extract both the byte signature and the hash signature of malwares from its network flow with low false positive and zero false negative. Our evaluation shows that AutoMal can generate strongly noise-resisted signatures that exactly depict the characteristics of malware. Copyright (c) 2014 John Wiley & Sons, Ltd.
引用
收藏
页码:1845 / 1854
页数:10
相关论文
共 50 条
  • [21] Automatic Payload Signature Generation for Accurate Identification of Internet Applications and Application Services
    Sija, Baraka D.
    Shim, Kyu-Seok
    Kim, Myung-Sup
    KSII TRANSACTIONS ON INTERNET AND INFORMATION SYSTEMS, 2018, 12 (04): : 1572 - 1593
  • [22] Metagenomics-based signature clustering and interactive visualization analysis
    Araujo Santos, Vitor Cirilo
    Correa, Leandro
    Meiguins, Bianchi
    Oliveira, Guilherme
    Alves, Ronnie
    2018 INTERNATIONAL JOINT CONFERENCE ON NEURAL NETWORKS (IJCNN), 2018,
  • [23] Image Categorization Using a Heuristic Automatic Clustering Method Based on Hierarchical Clustering
    LaPlante, Francois
    Kardouchi, Mustapha
    Belacel, Nabil
    IMAGE ANALYSIS AND RECOGNITION (ICIAR 2015), 2015, 9164 : 150 - 158
  • [24] Automatic Optimization for a Clustering Based Approach to Support IT Management
    Bozdogan, Can
    Zincir-Heywood, A. Nur
    Gokcen, Yasemin
    2013 IFIP/IEEE INTERNATIONAL SYMPOSIUM ON INTEGRATED NETWORK MANAGEMENT (IM 2013), 2013, : 1233 - 1236
  • [25] AUTOMATIC TERRAIN SELECTION BASED ON CLUSTERING AND GENETIC ALGORITHM
    Zhang, Quan-Xin
    Zheng, Jian-Jun
    Ling, Hai-Yun
    Fan, Xiu-Mei
    PROCEEDINGS OF 2007 INTERNATIONAL CONFERENCE ON MACHINE LEARNING AND CYBERNETICS, VOLS 1-7, 2007, : 372 - +
  • [26] Clustering Based on Continuous Hopfield Network
    Xiao, Yao
    Zhang, Yashu
    Dai, Xiangguang
    Yan, Dongfang
    MATHEMATICS, 2022, 10 (06)
  • [27] Hierarchical Language Identification based on Automatic Language Clustering
    Yin, Bo
    Ambikairajah, Eliathamby
    Chen, Fang
    INTERSPEECH 2007: 8TH ANNUAL CONFERENCE OF THE INTERNATIONAL SPEECH COMMUNICATION ASSOCIATION, VOLS 1-4, 2007, : 1217 - 1220
  • [28] Graph Convolutional Network for Automatic Pigment Clustering of Cultural Heritage Artifacts
    Cao, Bei Grace
    Messinger, David W.
    ALGORITHMS, TECHNOLOGIES, AND APPLICATIONS FOR MULTISPECTRAL AND HYPERSPECTRAL IMAGING XXVIII, 2022, 12094
  • [29] Automatic Clustering Based on Invasive Weed Optimization Algorithm
    Chowdhury, Aritra
    Bose, Sandip
    Das, Swagatam
    SWARM, EVOLUTIONARY, AND MEMETIC COMPUTING, PT II, 2011, 7077 : 105 - +
  • [30] An Automatic Data Clustering Algorithm based on Differential Evolution
    Tsai, Chun-Wei
    Tai, Chiech-An
    Chiang, Ming-Chao
    2013 IEEE INTERNATIONAL CONFERENCE ON SYSTEMS, MAN, AND CYBERNETICS (SMC 2013), 2013, : 794 - 799