Correlating High- and Low-Level Features: Increased Understanding of Malware Classification

被引:0
作者
Banin, Sergii [1 ]
Dyrkolbotn, Geir Olav [1 ]
机构
[1] NTNU, Dept Informat Secur & Commun Technol, Gjovik, Norway
来源
ADVANCES IN INFORMATION AND COMPUTER SECURITY, IWSEC 2019 | 2019年 / 11689卷
关键词
Malware analysis; Malware classification; Information security; Low-level features; Hardware-based features;
D O I
10.1007/978-3-030-26834-3_9
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Malware brings constant threats to the services and facilities used by modern society. In order to perform and improve anti-malware defense, there is a need for methods that are capable of malware categorization. As malware grouped into categories according to its functionality, dynamic malware analysis is a reliable source of features that are useful for malware classification. Different types of dynamic features are described in literature [5,6,13]. These features can be divided into two main groups: high-level features (API calls, File activity, Network activity, etc.) and low-level features (memory access patterns, high-performance counters, etc). Low-level features bring special interest for malware analysts: regardless of the anti-detection mechanisms used by malware, it is impossible to avoid execution on hardware. As hardware-based security solutions are constantly developed by hardware manufacturers and prototyped by researchers, research on low-level features used for malware analysis is a promising topic. The biggest problem with low-level features is that they don't bring much information to a human analyst. In this paper, we analyze potential correlation between the low- and high-level features used for malware classification. In particular, we analyze n-grams of memory access operations found in [6] and try to find their relationship with n-grams of API calls. We also compare performance of API calls and memory access n-grams on the same dataset as used in [6]. In the end, we analyze their combined performance for malware classification and explain findings in the correlation between high- and low-level features.
引用
收藏
页码:149 / 167
页数:19
相关论文
共 28 条
  • [1] Multinomial malware classification via low-level features
    Banin, Sergii
    Dyrkolbotn, Geir Olav
    DIGITAL INVESTIGATION, 2018, 26 : S107 - S117
  • [2] Mural classification model based on high- and low-level vision fusion
    Cao, Jianfang
    Cui, Hongyan
    Zhang, Zibang
    Zhao, Aidi
    HERITAGE SCIENCE, 2020, 8 (01)
  • [3] Mural classification model based on high- and low-level vision fusion
    Jianfang Cao
    Hongyan Cui
    Zibang Zhang
    Aidi Zhao
    Heritage Science, 8
  • [4] FUSION OF LOW- AND HIGH- LEVEL FEATURES FOR UAV HYPERSPECTRAL IMAGE CLASSIFICATION
    Zhang, Shuang
    Zhang, Xuming
    Zhang, Aizhu
    Fu, Hang
    Cheng, Ji
    Huang, Hui
    Sun, Genyun
    Zhang, Li
    Yao, Yanjuan
    2019 10TH WORKSHOP ON HYPERSPECTRAL IMAGING AND SIGNAL PROCESSING - EVOLUTION IN REMOTE SENSING (WHISPERS), 2019,
  • [5] Hardware-Based Malware Detection Using Low-Level Architectural Features
    Ozsoy, Meltem
    Khasawneh, Khaled N.
    Donovick, Caleb
    Gorelik, Iakov
    Abu-Ghazaleh, Nael
    Ponomarev, Dmitry
    IEEE TRANSACTIONS ON COMPUTERS, 2016, 65 (11) : 3332 - 3344
  • [6] Exploration of the Relationships Among Narcissism, Life Satisfaction, and Loneliness of Instagram Users and the High- and Low-Level Features of Their Photographs
    Kim, Yunhwan
    Nan, Dongyan
    Kim, Jang Hyun
    FRONTIERS IN PSYCHOLOGY, 2021, 12
  • [7] Automatic Image Annotation Based on Low-Level Features and Classification of the Statistical Classes
    Bronevich, Andrey
    Melnichenko, Alexandra
    ROUGH SETS, FUZZY SETS, DATA MINING AND GRANULAR COMPUTING, RSFDGRC 2011, 2011, 6743 : 314 - 321
  • [8] Assessing Local Low-level Features with Segmentation
    Yong, Suet-Peng
    INTERNATIONAL SYMPOSIUM ON ROBOTICS AND INTELLIGENT SENSORS 2012 (IRIS 2012), 2012, 41 : 405 - 411
  • [9] A Comparison of Low-level Features for Visual Attribute Recognition
    Danaci, Emine Gul
    Ikizler Cinbis, Nazli
    2015 23RD SIGNAL PROCESSING AND COMMUNICATIONS APPLICATIONS CONFERENCE (SIU), 2015, : 2038 - 2041
  • [10] Low-level features for visual attribute recognition: An evaluation
    Danaci, Emine Gul
    Ikizler-Cinbis, Nazli
    PATTERN RECOGNITION LETTERS, 2016, 84 : 185 - 191