AutoMal: automatic clustering and signature generation for malwares based on the network flow

被引:1
|
作者
Hao, Sun [1 ,2 ]
Wang, Wen [1 ]
Lu, Huabiao [1 ]
Ren, Peige [1 ]
机构
[1] Natl Univ Def Technol, Sch Comp, Changsha, Hunan, Peoples R China
[2] Natl Univ Def Technol, Natl Key Lab Parallel & Distributed Proc, Changsha, Hunan, Peoples R China
基金
美国国家科学基金会; 国家高技术研究发展计划(863计划);
关键词
network malware; clustering; signature generation; matrix; feature hashing;
D O I
10.1002/sec.1029
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The volume of malwares is growing at an exponential speed nowadays. This huge growth makes it extremely hard to analyse malware manually. Most existing signatures extracting methods are based on string signatures, and string matching is not accurate and time consuming. Therefore, this paper presents AutoMal, a system for automatically extracting signatures from large-scale malwares. Firstly, the system proposes to represent the network flows by using feature hashing, which can dramatically reduce the high-dimensional feature spaces that are general in malware analysis. Then, we design a clustering and median filtering method to classify the malware vectors into different types. Finally, it introduces the signature generation algorithm based on Bayesian method. The system can extract both the byte signature and the hash signature of malwares from its network flow with low false positive and zero false negative. Our evaluation shows that AutoMal can generate strongly noise-resisted signatures that exactly depict the characteristics of malware. Copyright (c) 2014 John Wiley & Sons, Ltd.
引用
收藏
页码:1845 / 1854
页数:10
相关论文
共 50 条
  • [41] Variable Neighborhood Search for Automatic Density-Based Clustering
    Boudane, Fatima
    Berrichi, Ali
    PROCEEDINGS OF THE 2017 INTERNATIONAL CONFERENCE ON MATHEMATICS AND INFORMATION TECHNOLOGY (ICMIT), 2017, : 141 - 147
  • [42] The automatic recognition based on the grade relationship between words of clustering
    Hu, Juxiang
    Lv, Xueqiang
    Xu, Liping
    PROCEEDINGS OF THE FIRST INTERNATIONAL CONFERENCE ON INFORMATION SCIENCES, MACHINERY, MATERIALS AND ENERGY (ICISMME 2015), 2015, 126 : 1361 - 1366
  • [43] A symmetry based multiobjective clustering technique for automatic evolution of clusters
    Saha, Sriparna
    Bandyopadhyay, Sanghamitra
    PATTERN RECOGNITION, 2010, 43 (03) : 738 - 751
  • [44] Efficient Clustering Network Based on Matrix Factorization
    Cheng, Jieren
    Li, Jimei
    Zeng, Faqiang
    Tao, Zhicong
    Yang, Yue
    CMC-COMPUTERS MATERIALS & CONTINUA, 2024, 80 (01): : 281 - 298
  • [45] HTTP Cyberattacks Detection through Automatic Signature Generation in multi-site IoT Deployments
    Lara, Agustin W.
    Ternero, J. A.
    Estepa Alonso, Rafael
    Estepa Alonso, Antonio
    Ruiz-Robles, Fernando
    Diaz-Verdejo, Jesus E.
    PROCEEDINGS OF THE 2023 EUROPEAN INTERDISCIPLINARY CYBERSECURITY CONFERENCE, EICC 2023, 2023, : 65 - 70
  • [46] Evolution-based tabu search approach to automatic clustering
    Pan, Shih-Ming
    Cheng, Kuo-Sheng
    IEEE TRANSACTIONS ON SYSTEMS MAN AND CYBERNETICS PART C-APPLICATIONS AND REVIEWS, 2007, 37 (05): : 827 - 838
  • [47] An Automatic Recognition Approach of Constellation Satellites' Usability Based on Clustering
    An, Xinyuan
    Chen, Jun
    Liu, Yi
    Li, Wei
    Chen, Haibo
    2013 10TH INTERNATIONAL CONFERENCE ON FUZZY SYSTEMS AND KNOWLEDGE DISCOVERY (FSKD), 2013, : 919 - 923
  • [48] Automatic Heart Sound Segmentation Method Based on Cyclostationarity and Clustering
    Li, Ting
    PROCEEDINGS OF THE 4TH INTERNATIONAL CONFERENCE ON MECHATRONICS, MATERIALS, CHEMISTRY AND COMPUTER ENGINEERING 2015 (ICMMCCE 2015), 2015, 39 : 361 - 366
  • [49] Pattern-based Automatic Parallelization of Representative-based Clustering Algorithms
    Islam, Saiyedul
    Balasubramaniam, Sundar
    Gupta, Shruti
    Brajesh, Shikhar
    Badlani, Rohan
    Labhishetty, Nitin
    Baid, Abhinav
    Goyal, Poonam
    Goyal, Navneet
    2018 IEEE 5TH INTERNATIONAL CONFERENCE ON DATA SCIENCE AND ADVANCED ANALYTICS (DSAA), 2018, : 99 - 108
  • [50] Clustering-Based Prototype Generation For Imbalance Classification
    Ren, Huajuan
    Yang, Bei
    2019 INTERNATIONAL CONFERENCE ON SMART GRID AND ELECTRICAL AUTOMATION (ICSGEA), 2019, : 422 - 426