Detecting Malware with Information Complexity.

Detecting Malware with Information Complexity.
复制标题

DOI:
10.3390/e22050575
复制
发表时间:
2020-05-20
期刊:
Entropy (Basel, Switzerland)
影响因子:
--
通讯作者:
Menéndez HD
Menéndez HD
中科院分区:
其他
文献类型:
--
作者:
Alshahwan N;Barr ET;Clark D;Danezis G;Menéndez HD

文献摘要

参考文献

被引文献

相似文献

恶意软件隐藏是恶意软件传播的主要策略。黑帽子基于多态性和变质性创造了恶意软件的变体。根据定义,恶意软件变体共享一些信息。尽管隐藏策略改变了这些信息,但该软件仍然存在模式。考虑到标有恶意软件和良性软件的动物园,我们询问可疑程序是否与恶意软件或良性软件更相似。归一化压缩距离(NCD)是一个通用度量标准,可测量两个字符串的共享信息内容。这项措施在恶意软件武器竞赛中打开了一个新的阵线,其中对策对恶意软件作家的成本更高,现在他们必须将模式作为字符串qua字符串混淆,而无需参考执行方式。我们的方法以97.4%的精度和3%的误报率对磁盘居住的恶意软件进行了分类。我们证明,通过将NCD与使用决策林相结合的可执行文件率可以提高其准确性,从而为未来的改进铺平了道路。我们证明,在几天的狭窄时间范围内报道的恶意软件比两年内报道的恶意软件更均匀,但是我们的方法仍然以95.2%的精度和5%的假阳性率对后者进行了分类。由于使用压缩,我们方法的时间和计算成本是不平凡的。我们表明,简单的近似技术可以提高其运行时间高达63%。我们将我们的结果与将Virustotal网站上59个反恶意软件程序应用于我们的恶意软件的结果进行了比较。我们的方法的表现优于每个单独使用的方法,并匹配所有方法。
Malware concealment is the predominant strategy for malware propagation. Black hats create variants of malware based on polymorphism and metamorphism. Malware variants, by definition, share some information. Although the concealment strategy alters this information, there are still patterns on the software. Given a zoo of labelled malware and benign-ware, we ask whether a suspect program is more similar to our malware or to our benign-ware. Normalized Compression Distance (NCD) is a generic metric that measures the shared information content of two strings. This measure opens a new front in the malware arms race, one where the countermeasures promise to be more costly for malware writers, who must now obfuscate patterns as strings qua strings, without reference to execution, in their variants. Our approach classifies disk-resident malware with 97.4% accuracy and a false positive rate of 3%. We demonstrate that its accuracy can be improved by combining NCD with the compressibility rates of executables using decision forests, paving the way for future improvements. We demonstrate that malware reported within a narrow time frame of a few days is more homogeneous than malware reported over two years, but that our method still classifies the latter with 95.2% accuracy and a 5% false positive rate. Due to its use of compression, the time and computation cost of our method is nontrivial. We show that simple approximation techniques can improve its running time by up to 63%. We compare our results to the results of applying the 59 anti-malware programs used on the VirusTotal website to our malware. Our approach outperforms each one used alone and matches that of all of them used collectively.
DOI: 10.1109/tkde.2013.57
发表时间: 2014-04-01
影响因子: 8.9
作者:
Biggio, Battista;Fumera, Giorgio;Roli, Fabio
通讯作者: Roli, Fabio
DOI: 10.1501/0000000035
发表时间: 2011-01-01
影响因子: 36.5
作者:
Criminisil, Antonio;Shotton, Jamie;Konukoglu, Ender
通讯作者: Konukoglu, Ender
DOI: 10.3390/e21050513
发表时间: 2019-05-21
期刊: Entropy (Basel, Switzerland)
影响因子: --
作者:
Menéndez HD;Llorente JL
通讯作者: Llorente JL
DOI: 10.1109/tpami.2004.1262185
发表时间: 2004-02-01
影响因子: 23.6
作者:
Fowlkes, C;Belongie, S;Malik, J
通讯作者: Malik, J
DOI: 10.1109/tit.2004.838101
发表时间: 2004-12-01
影响因子: 2.5
作者:
Li, M;Chen, X;Vitányi, PMB
通讯作者: Vitányi, PMB