Based on Multi-features and Clustering Ensemble Method for Automatic Malware Categorization

Based on Multi-features and Clustering Ensemble Method for Automatic Malware Categorization
复制标题

基于多特征和聚类集成方法的恶意软件自动分类

DOI:
10.1109/trustcom/bigdatase/icess.2017.222
复制
发表时间:
2017
期刊:
2017 IEEE Trustcom/BigDataSE/ICESS
影响因子:
--
通讯作者:
Jianguo Jiang
Jianguo Jiang
中科院分区:
--
文献类型:
--
作者:
Yunan Zhang;Chenghao Rong;Qingjia Huang;Yang Wu;Zeming Yang;Jianguo Jiang

文献摘要

被引文献

相似文献

恶意软件的自动分类对于打击当前大量的恶意软件和辅助相应的取证具有重要的作用。通常,使用静态工具和动态沙箱可以提取大量的样本信息来进行恶意软件分析。将所获得的这些特征有效地结合起来进行进一步分析,将为我们提供更好的理解。另一方面,目前大多数恶意软件分析工作都是基于单一类别的机器学习算法来对样本进行分类。然而,不同的聚类算法各有优缺点。然后,如何结合多类别特征和算法的优点来进一步提高分析结果是非常关键的。在本文中,我们提出了一种新的可扩展的恶意软件分析框架,以利用不同特征和算法的互补性来优化整合它们的结果。通过使用聚类集成的概念,我们的系统结合了单独类别特征的划分和算法,以获得更好的质量和稳健性。我们的系统由以下三部分组成:(1)提取多类别的静态和动态特征;(2)使用k-均值和层次聚类算法构建基本聚类;(3)提出了一种基于混合模型聚类集成的高效方法来进行有效的聚类分析。我们已经在两个恶意软件数据集上对我们的方法进行了评估,即微软恶意软件数据集和我们自己的恶意软件数据集,这两个数据集分别包含10868个和53760个样本。实验结果表明,该方法能够较好地对恶意软件进行分类,具有较好的质量和鲁棒性。此外,与目前最先进的恶意软件分析工作相比,我们的方法在系统运行时间和内存消耗方面也有一定的优势
Automatic malware categorization plays an important role in combating the current large volume of malware and aiding the corresponding forensics. Generally, there are lot of sample information could be extracted with the static tools and dynamic sandbox for malware analysis. Combine these obtained features effectively for further analysis would provides us a better understanding. On the other hand, most current works on malware analysis are based on single category of machine learning algorithm to categorize samples. However, different clustering algorithms have their own strengths and weaknesses. And then, how to combine the merits of the multiple categories of features and algorithms to further improve the analysis result is very critical. In this paper, we propose a novel scalable malware analysis framework to exploit the complementary nature of different features and algorithms to optimally integrate their results. By using the concept of clustering ensemble, our system combines partitions from individual category of feature and algorithm to obtain better quality and robustness. Our system composed of the following three parts: (1) extract multiple categories of static and dynamic features; (2) use the k-means and hierarchical clustering algorithms to construct the base clustering; (3) proposed an efficient method based on mixture model clustering ensemble to conduct an effective clustering analysis. We have evaluated our method on two malware datasets, namely the Microsoft malware dataset and our own malware dataset which contained 10868 and 53760 samples respectively. Our experiment results show that our method could categorize malware with better quality and robustness. Also, our method has certain advantages in the system run time and memory consumption compared with the state-of-the art malware analysis works