ISMCS: An intelligent instruction sequence based malware categorization system

ISMCS: An intelligent instruction sequence based malware categorization system
复制标题

ISMCS:基于智能指令序列的恶意软件分类系统

DOI:
--
复制
发表时间:
2009
期刊:
2009 3rd International Conference on Anti-counterfeiting, Security, and Identification in Communication
影响因子:
--
通讯作者:
Qinshan Jiang
Qinshan Jiang
中科院分区:
--
文献类型:
--
作者:
Kaiming Huang;Yanfang Ye;Qinshan Jiang

文献摘要

被引文献

相似文献

近年来,自动化恶意软件(如病毒、后门程序、间谍软件、木马和蠕虫)分类方法以及行业通用命名规范,成为了计算机安全领域备受关注的话题。基于对基于功能的指令序列的分析,我们运用一种新颖的加权子空间聚类方法,开发了一个基于智能指令序列的恶意软件分类系统(ISMCS)。ISMCS是一个集成系统,由三个主要模块组成:特征提取器、使用加权子空间聚类方法的恶意软件分类器以及恶意软件特征码生成器。ISMCS不仅能够有效地将恶意软件分类到不同家族,还能自动为每个家族生成统一的特征码。颇具前景的实验结果表明,我们的ISMCS系统的有效性优于其他现有的恶意软件分类方法,如K均值算法和层次聚类算法。
Recently, automated malware (e.g., viruses, backdoors, spyware, Trojans and worms) categorization methods and an industry-wide naming convention have been the computer security topics that are of great interest. Resting on the analysis of function based instruction sequence, we develop an intelligent instruction sequence based malware categorization system (ISMCS) using a novel weighted subspace clustering method. ISMCS is an integrated system consisting of three major modules: feature exactor, malware categorizer using weighted subspace clustering method and malware signature generator. ISMCS can not only effectively categorize malwares to different families, but also automatically generate the unify signature for every family. Promising experimental results demonstrate that the effectiveness of our ISMCS system outperform other existing malware categorization methods, such as K-Means and hierarchical clustering algorithms.