A Malware Classification Method Based on Generic Malware Information

A Malware Classification Method Based on Generic Malware Information
复制标题

一种基于通用恶意软件信息的恶意软件分类方法

DOI:
--
复制
发表时间:
2015
期刊:
International Conference on Neural Information Processing
影响因子:
--
通讯作者:
Jungsuk Song
Jungsuk Song
中科院分区:
--
文献类型:
--
作者:
Jiyeon Choi;Heeseok Kim;Jangwon Choi;Jungsuk Song

文献摘要

被引文献

相似文献

由于攻击者很容易使用专用的恶意软件生成工具来制作恶意软件,因此恶意软件的数量正在迅速增加。然而,由于恶意软件数量的增加,很难分析所有恶意软件。为此,许多研究人员提出了恶意软件分类方法,对新的和已知的恶意软件类型进行分类,以便集中精力分析新的恶意软件。现有的方法大多试图找出好的特征,作为计算恶意软件之间相似度的标准,以提高分类的准确性。因此,这些方法通过进行静态和动态分析来提取包括恶意行为信息在内的特征,但分析许多恶意软件本身需要花费太多的时间和精力。在本文中,我们提出了一种恶意软件分类方法,用于使用通用恶意软件信息从大规模恶意软件中查找新类型。所提出的方法可以用于预处理,以帮助现有方法减少恶意软件分析和分类所花费的时间。利用imphash提高了恶意软件的分类准确率,并证明基于imphash的分类准确率超过99%,同时保持较低的误报率。
Since attackers easily have been making malware using dedicated malware generation tools, the number of malware is increasing rapidly. However, it is hard to analyze all malwares because of rise in high-volume of malwares. For this reason, many researchers have proposed the malware classification methods for classifying new and well-known types of malwares in order to focus on analyzing new malwares. The existing methods mostly try to find out good features which are used as a criterion of calculating a similarity between malwares for improving a classification accuracy. So, these methods extract the features including malicious behavior information by performing static and dynamic analysis, but analyzing many malwares itself spends too much time and efforts. In this paper, we propose a malware classification method for finding new types from large scale malwares using generic malware information. Proposed method can be used for a pre-step so as to help the existing methods reduce the spending time in analysis and classification for malwares. It improve the classificaion accuracy of malwares by using an imphash and proved a classification accuracy based on the imphash is more than 99i¾ź% while maintaining a low false positive rate.