PE-Header-Based Malware Study and Detection

PE-Header-Based Malware Study and Detection
复制标题

基于 PE 标头的恶意软件研究和检测

DOI:
--
复制
发表时间:
2012
期刊:
影响因子:
--
通讯作者:
Yibin Liao
Yibin Liao
中科院分区:
--
文献类型:
--
作者:
Yibin Liao

文献摘要

被引文献

相似文献

在本文中,我提出了一个简单而快速的approach来区分恶意软件和合法的.exe文件,只需查看MS Windows可移植可执行文件(PE)头的属性。我们提取区分功能的PEheader使用的结构信息标准化的微软Windows操作系统的可执行文件。我使用了以下三种方法:(1)使用WebSpider从两个网站www.downloads.com和www.softpedia.com收集了大量的malware .exe和legal.exe数据集,(2)使用PE-Header-Parser提取每个头字段的特征,比较并找到恶意软件和合法.exe文件之间的最显著差异,(3)使用Icon-Extractor从PE中提取图标,从malware .exe文件中找到最常见的图标。我已经评估了我们的approach上的一个大型数据集,其中包含5598恶意软件样本和1237合法样本分别。我们的实验结果表明,基于PEHeader-Based方法实现了超过99%的检测率小于0.2%的误报区分良性和恶意的可执行文件在不到20分钟。我们还发现了3种在合法PE文件中很少看到的恶意软件最流行的图标,以及8种恶意软件的误导性图标。我的研究结果表明,通过简单地查看PE标头中的一些关键特征,可以识别恶意软件。
In this paper, I present a simple and faster apporach to distinguish between malware and legitimate .exe files by simply looking at properties of the MS Windows Portable Executable (PE) headers. We extract distinguishing features from the PEheaders using the structural information standardized by the Miscrosoft Windows operating system for executables. I use the following three methodology: (1) collect a large dataset of malware .exe and legitimate .exe from the two website, www.downloads.com and www.softpedia.com by using a WebSpider, (2) use a PE-Header-Parser to extract the features of each header field, compare and find the most significant difference between malware and legitimate .exe files, (3) use a Icon-Extractor to extract the icons from the PE, find the most prevalent icons from the malware .exe files. I have evaluated our apporach on a large dataset which contains 5598 malware samples and 1237 legitimate samples respectively. The result of our experiments show that the PEHeader-Based approach achieves more than 99% detection rate with less than 0.2% false positive for distinguishing between benign and malicious executables in less than 20 minutes. We have also found 3 most prevalent icons from malware that are seldom seen in legitimate PE files, and 8 types of misleading icons from malware. My results show that it is possible to identify the malware by simply looking at some key features from PE headers.