Efficient Malware Packer Identification Using Support Vector Machines with Spectrum Kernel

被引:7
作者
Ban, Tao [1 ]
Isawa, Ryoichi [1 ]
Guo, Shanqing [2 ]
Inoue, Daisuke [1 ]
Nakao, Koji [1 ]
机构
[1] Natl Inst Informat & Commun Technol, 4-2-1 Nukuikitamachi, Koganei, Tokyo 1848795, Japan
[2] Shandong Univ, Jinan, Peoples R China
来源
2013 EIGHTH ASIA JOINT CONFERENCE ON INFORMATION SECURITY (ASIAJCIS) | 2013年
关键词
CLASSIFICATION; EXECUTABLES;
D O I
10.1109/ASIAJCIS.2013.18
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Packing is among the most popular obfuscation techniques to impede anti-virus scanners from successfully detecting malware. Efficient and automatic packer identification is an essential step to perform attack on ever increasing malware databases. In this paper we present a p-spectrum induced linear Support Vector Machine to implement an automated packer identification with good accuracy and scalability. The efficacy and efficiency of the method is evaluated on a dataset composed of 3228 packed files created by 25 packers with near-perfect identification results reported. This method can help to improve the scanning efficiency of anti-virus products and ease efficient back-end malware research.
引用
收藏
页码:69 / 76
页数:8
相关论文
共 24 条
[1]  
Ban I. R. G. S. I. D., 2013, IJCNN 13
[2]  
bart, 2005, FSG F AST S MALL G O
[3]   LIBSVM: A Library for Support Vector Machines [J].
Chang, Chih-Chung ;
Lin, Chih-Jen .
ACM TRANSACTIONS ON INTELLIGENT SYSTEMS AND TECHNOLOGY, 2011, 2 (03)
[4]   GEOMETRICAL AND STATISTICAL PROPERTIES OF SYSTEMS OF LINEAR INEQUALITIES WITH APPLICATIONS IN PATTERN RECOGNITION [J].
COVER, TM .
IEEE TRANSACTIONS ON ELECTRONIC COMPUTERS, 1965, EC14 (03) :326-&
[5]  
Dwing, 2006, WIN 0 39FINAL
[6]  
Fan RE, 2008, J MACH LEARN RES, V9, P1871
[7]  
Guo FL, 2008, LECT NOTES COMPUT SC, V5230, P98
[8]   A METHOD FOR THE CONSTRUCTION OF MINIMUM-REDUNDANCY CODES [J].
HUFFMAN, DA .
PROCEEDINGS OF THE INSTITUTE OF RADIO ENGINEERS, 1952, 40 (09) :1098-1101
[9]  
Joachims T, 1999, ADVANCES IN KERNEL METHODS, P169
[10]  
Joachims T., 2006, P 12 ACM SIGKDD INT, P217, DOI [10.1145/1150402.1150429, DOI 10.1145/1150402.1150429]