Malware Classification Based on Dynamic Behavior

George Cabau, Magda Buhu, Ciprian Oprișa
{"title":"Malware Classification Based on Dynamic Behavior","authors":"George Cabau, Magda Buhu, Ciprian Oprișa","doi":"10.1109/SYNASC.2016.057","DOIUrl":null,"url":null,"abstract":"Automated file analysis is important in malware research for identifying malicious files in large collection of samples. This paper describes an automatic system that can classify a file as infected based on the dynamic behavior of the file observed inside a controlled monitored environment. Based on features revealed at runtime, we train a Support Vector Machine classifier that can be further used to identify malicious files. The paper analyses the classifier performance based on several types of features, from raw runtime information to heuristics generated by expert systems and provides guidelines for the features selection process when dealing with this type of data. We show that by enlarging the features domain, our classifier gains proactivity and is able to detect previously unseen samples, even if they belong to different malware families.","PeriodicalId":268635,"journal":{"name":"2016 18th International Symposium on Symbolic and Numeric Algorithms for Scientific Computing (SYNASC)","volume":"46 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2016-09-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"17","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2016 18th International Symposium on Symbolic and Numeric Algorithms for Scientific Computing (SYNASC)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/SYNASC.2016.057","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 17

Abstract

Automated file analysis is important in malware research for identifying malicious files in large collection of samples. This paper describes an automatic system that can classify a file as infected based on the dynamic behavior of the file observed inside a controlled monitored environment. Based on features revealed at runtime, we train a Support Vector Machine classifier that can be further used to identify malicious files. The paper analyses the classifier performance based on several types of features, from raw runtime information to heuristics generated by expert systems and provides guidelines for the features selection process when dealing with this type of data. We show that by enlarging the features domain, our classifier gains proactivity and is able to detect previously unseen samples, even if they belong to different malware families.
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
基于动态行为的恶意软件分类
在恶意软件研究中,自动文件分析对于识别大量样本中的恶意文件非常重要。本文描述了一个自动系统,该系统可以根据在受控监控环境中观察到的文件的动态行为对文件进行感染分类。基于运行时显示的特征,我们训练了一个支持向量机分类器,该分类器可以进一步用于识别恶意文件。本文分析了基于几种类型特征的分类器性能,从原始运行时信息到专家系统生成的启发式,并为处理这类数据时的特征选择过程提供了指导。我们表明,通过扩大特征域,我们的分类器获得了主动性,并且能够检测到以前未见过的样本,即使它们属于不同的恶意软件家族。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
A Hybrid CPU/GPU Approach for the Parallel Algebraic Recursive Multilevel Solver pARMS Continuation Semantics of a Language Inspired by Membrane Computing with Symport/Antiport Interactions Parallel Integer Polynomial Multiplication A Numerical Method for Analyzing the Stability of Bi-Parametric Biological Systems Comparing Different Term Weighting Schemas for Topic Modeling
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1