Identifying metamorphic virus using n-grams and Hidden Markov Model

Identifying metamorphic virus using n-grams and Hidden Markov Model
复制标题

使用 n-gram 和隐马尔可夫模型识别变态病毒

DOI:
--
复制
发表时间:
2015
期刊:
International Conference on Advances in Computing, Communications and Informatics
影响因子:
--
通讯作者:
Raghu Neelisetti
Raghu Neelisetti
中科院分区:
--
文献类型:
--
作者:
Shiva Prasad Thunga;Raghu Neelisetti

文献摘要

被引文献

相似文献

计算机病毒是对计算社区快速发展的威胁。这些病毒分为不同的类别,人们普遍认为变态病毒极难检测。有效对抗病毒的第一步是成功对其家族进行分类,以便可以轻松应用过去的经验来了解其功能并应用正确的策略来缓解病毒。在本文中,我们提出并测试了一种基于隐马尔可夫模型(HMM)的分类器,该分类器可用于识别病毒候选者所属的家族。所提出的解决方案是训练多个HMM,每个HMM代表一个病毒家族,然后根据获得的对数似然相似度得分确定要识别的病毒家族。来自 malicia 数据集的恶意软件样本用于评估所提出的技术。
Computer virus is a rapidly evolving threat to the computing community. These viruses fall into different categories and it is generally believed that metamorphic viruses are extremely difficult to detect. The first step to effectively combat a virus is to successfully classify it's family so that past experience can be readily applied to understand it's functionality and apply the right strategy to mitigate it. In this paper we propose and test a Hidden Markov Model (HMM) based classifier that can be used to identify the family to which a virus understudy belongs to. The proposed solution is to train multiple HMM's, each representing a family of virus and then determine the family of the virus to be identified based on the log-likelihood similarity score obtained. Malware samples from the malicia data set were used to evaluate the proposed technique.