Control Flow Graph Based Multiclass Malware Detection Using Bi-normal Separation

被引:17
作者
Kapoor, Akshay [1 ]
Dhavale, Sunita [1 ]
机构
[1] Def Inst Adv Technol, Dept Comp Engn, Girinagar 411025, India
关键词
separation; control flow graph; machine learning; malware detection;
D O I
10.14429/dsj.66.9701
中图分类号
O [数理科学和化学]; P [天文学、地球科学]; Q [生物科学]; N [自然科学总论];
学科分类号
07 ; 0710 ; 09 ;
摘要
Control flow graphs (CFG) and OpCodes extracted from disassembled executable files are widely used for malware detection. Most of the research in static analysis is focused on binary class malware detection which only classifies an executable as benign or malware. To overcome this issue, CFG based multiclass malware detection system that automatically classifies the malware into their respective families is proposed. The use Bi-normal separation (BNS) as a feature scoring metric. Experimental results show that proposed method using BNS outperforms compared to hitherto use technique of document Frequency for multiclass metamorphic malware detection and achieves detection accuracy of 99.5 per cent.
引用
收藏
页码:138 / 145
页数:8
相关论文
共 14 条
[1]   Improving support vector machine classifiers by modifying kernel functions [J].
Amari, S ;
Wu, S .
NEURAL NETWORKS, 1999, 12 (06) :783-789
[2]   Opcodes as predictor for malware [J].
Bilar, Daniel .
INTERNATIONAL JOURNAL OF ELECTRONIC SECURITY AND DIGITAL FORENSICS, 2007, 1 (02) :156-168
[3]  
Bruschi D, 2006, LECT NOTES COMPUT SC, V4064, P129
[4]   Control flow-based opcode behavior analysis for Malware detection [J].
Ding, Yuxin ;
Dai, Wei ;
Yan, Shengli ;
Zhang, Yumei .
COMPUTERS & SECURITY, 2014, 44 :65-74
[5]  
Forman G., 2003, Journal of Machine Learning Research, V3, P1289, DOI 10.1162/153244303322753670
[6]  
Forman George., 2008, PROCEEDING 17 ACM C, P263, DOI DOI 10.1145/1458082.1458119
[7]  
Furnkranz Johannes, 1998, AAAI ICML WORKSH LEA
[8]  
Kolter J. Z., 2004, KDD 2004, P470
[9]  
Moskovitch R, 2008, LECT NOTES COMPUT SC, V5376, P204, DOI 10.1007/978-3-540-89900-6_21
[10]   TERM-WEIGHTING APPROACHES IN AUTOMATIC TEXT RETRIEVAL [J].
SALTON, G ;
BUCKLEY, C .
INFORMATION PROCESSING & MANAGEMENT, 1988, 24 (05) :513-523