Unveiling Zeus: automated classification of malware samples

Unveiling Zeus: automated classification of malware samples
复制标题

揭晓 Zeus:恶意软件样本的自动分类

DOI:
--
复制
发表时间:
2013
期刊:
The Web Conference
影响因子:
--
通讯作者:
Omar Alrawi
Omar Alrawi
中科院分区:
--
文献类型:
--
作者:
Aziz Mohaisen;Omar Alrawi

文献摘要

被引文献

相似文献

恶意软件家族分类是许多反病毒(AV)公司已经解决的一个古老问题。有两种常用的分类技术,基于签名和基于行为。基于签名的分类使用出现在二进制代码中的常见字节序列来识别和检测恶意软件家族。基于行为的分类使用由恶意软件在执行期间创建的工件来进行识别。在本文中,我们报告了一个独特的数据集,我们从我们的操作中获得,并使用基于行为的方法使用几种机器学习技术进行分类。我们感兴趣的主要恶意软件分类是流行的Zeus恶意软件。对于其分类,我们确定了65个特征,这些特征对于识别恶意软件家族是独特和强大的。我们表明,像文件系统,注册表和网络功能的工件可以用来识别不同的恶意软件家族具有很高的准确性-在某些情况下高达95%。
Malware family classification is an age old problem that many Anti-Virus (AV) companies have tackled. There are two common techniques used for classification, signature based and behavior based. Signature based classification uses a common sequence of bytes that appears in the binary code to identify and detect a family of malware. Behavior based classification uses artifacts created by malware during execution for identification. In this paper we report on a unique dataset we obtained from our operations and classified using several machine learning techniques using the behavior-based approach. Our main class of malware we are interested in classifying is the popular Zeus malware. For its classification we identify 65 features that are unique and robust for identifying malware families. We show that artifacts like file system, registry, and network features can be used to identify distinct malware families with high accuracy - in some cases as high as 95 percent.