Leveraging Compression-Based Graph Mining for Behavior-Based Malware Detection

Leveraging Compression-Based Graph Mining for Behavior-Based Malware Detection
复制标题

利用基于压缩的图挖掘进行基于行为的恶意软件检测

DOI:
--
复制
发表时间:
2019
影响因子:
7.3
通讯作者:
A. Pretschner
A. Pretschner
中科院分区:
计算机科学2区
文献类型:
--
作者:
Tobias Wüchner;Aleksander Cislak;Martín Ochoa;A. Pretschner

文献摘要

被引文献

相似文献

基于行为的检测方法通常解决静态混淆恶意软件的威胁。这样的方法通常使用图来表示进程或系统行为,并且通常采用基于频率的图挖掘技术来从恶意软件图的集合中提取特征模式。分子挖掘领域的最新研究表明,基于频率的图挖掘算法在发现高分辨模式时往往表现不佳。我们提出了一种新的恶意软件检测方法,使用所谓的基于压缩的挖掘定量数据流图,以获得高度准确的检测模型。我们对大量不同恶意软件集的评估表明,我们的方法在检测有效性方面超过基于频率的检测模型600%以上。
Behavior-based detection approaches commonly address the threat of statically obfuscated malware. Such approaches often use graphs to represent process or system behavior and typically employ frequency-based graph mining techniques to extract characteristic patterns from collections of malware graphs. Recent studies in the molecule mining domain suggest that frequency-based graph mining algorithms often perform sub-optimally in finding highly discriminating patterns. We propose a novel malware detection approach that uses so-called compression-based mining on quantitative data flow graphs to derive highly accurate detection models. Our evaluation on a large and diverse malware set shows that our approach outperforms frequency-based detection models in terms of detection effectiveness by more than 600 percent.