A graph theoretic approach to fast and accurate malware detection

A graph theoretic approach to fast and accurate malware detection
复制标题

快速准确检测恶意软件的图论方法

DOI:
--
复制
发表时间:
2017
期刊:
2017 IFIP Networking Conference (IFIP Networking) and Workshops
影响因子:
--
通讯作者:
A. Liu
A. Liu
中科院分区:
--
文献类型:
--
作者:
Zubair Shafiq;A. Liu

文献摘要

被引文献

相似文献

由于先前未知的恶意软件的签名不可用,非签名恶意软件检测方案通常依赖于分析程序行为。基于先前行为的非签名恶意软件检测方案要么容易通过混淆来规避,要么在存储空间和检测时间方面非常低效。在本文中,我们提出了GZero,一个图论方法快速,准确的非签名恶意软件检测在终端主机。GZero在存储空间和检测时间方面都是有效的。我们对大量的良性软件和恶意软件进行了实验。我们的研究结果表明,GZero实现了超过99%的检测率和小于1%的误报率,每个程序的平均扫描时间小于1秒,并且对混淆攻击相对稳健。由于其低开销,GZero可以补充终端主机上现有的恶意软件检测解决方案。
Due to the unavailability of signatures for previously unknown malware, non-signature malware detection schemes typically rely on analyzing program behavior. Prior behavior based non-signature malware detection schemes are either easily evadable by obfuscation or are very inefficient in terms of storage space and detection time. In this paper, we propose GZero, a graph theoretic approach fast and accurate non-signature malware detection at end hosts. GZero it is effective while being efficient in terms of both storage space and detection time. We conducted experiments on a large set of both benign software and malware. Our results show that GZero achieves more than 99% detection rate and a false positive rate of less than 1%, with less than 1 second of average scan time per program and is relatively robust to obfuscation attacks. Due to its low overheads, GZero can complement existing malware detection solutions at end hosts.