首页> 外文会议>2012 IEEE/IPSJ 12th International Symposium on Applications and the Internet >A Malware Classification Method Based on Similarity of Function Structure
【24h】

A Malware Classification Method Based on Similarity of Function Structure

机译:基于功能结构相似度的恶意软件分类方法

获取原文
获取原文并翻译 | 示例

摘要

Malicious software (Malware) in form of Internet worms, computer viruses, and trojan horses poses a major threat to the security of network systems. Identification of malware variants provides great benefit in early detection. Taking into account that variants of malware families share similar functions reflecting its origin and purpose, we propose a method focusing on the features of functions that a malware program consists of. In our method, the feature database is created based on the analysis of known malware programs, and functions in unknown programs are compared to the content of the database to determine the program belong to what family. To decrease the cost of the calculation of similarity, we use a filtering algorithm based on one-class SVM to filter out functions which have small influence in determining the family. We evaluated the approach using 32 categorized malware samples and 113 malware samples to be classified. In the experiment, it is shown that our approach effectively reduce the time for calculation while the accuracy is not deteriorated too much.
机译:Internet蠕虫,计算机病毒和特洛伊木马形式的恶意软件(Malware)对网络系统的安全性构成了重大威胁。识别恶意软件变体在早期检测中提供了很大的好处。考虑到恶意软件家族的变体共享相似的功能以反映其起源和目的,我们提出一种方法,重点关注恶意软件程序所包含的功能的特征。在我们的方法中,特征数据库是基于对已知恶意软件程序的分析创建的,并将未知程序中的功能与数据库的内容进行比较,以确定该程序属于哪个家族。为了减少相似度计算的成本,我们使用基于一类SVM的过滤算法来过滤出对确定族群影响较小的函数。我们使用32个分类的恶意软件样本和113个要分类的恶意软件样本评估了该方法。在实验中表明,我们的方法有效地减少了计算时间,同时精度没有降低太多。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号