An approach for detection and family classification of malware based on behavioral analysis

Steven Strandlund Hansen, Thor Mark Tampus Larsen, Matija Stevanovic, Jens Myrup Pedersen

Publikation: Bidrag til bog/antologi/rapport/konference proceedingKonferenceartikel i proceedingForskningpeer review

90 Citationer (Scopus)

Abstract

Malware, i.e., malicious software, represents one of the main cyber security threats today. Over the last decade malware has been evolving in terms of the complexity of malicious software and the diversity of attack vectors. As a result modern malware is characterized by sophisticated obfuscation techniques, which hinder the classical static analysis approach. Furthermore, the increased amount of malware that emerges every day, renders a manual approach inefficient. This study tackles the problem of analyzing, detecting and classifying the vast amount of malware in a scalable, efficient and accurate manner. We propose a novel approach for detecting malware and classifying it to either known or novel, i.e., previously unseen malware family. The approach relies on Random Forests classifier for performing both malware detection and family classification. Furthermore, the proposed approach employs novel feature representations for malware classification, that significantly reduces the feature space, while achieving encouraging predictive performance. The approach was evaluated using behavioral traces of over 270,000 malware samples and 837 samples of benign software. The behavioral traces were obtained using a modified version of Cuckoo sandbox, that was able to harvest behavioral traces of the analyzed samples in a time-efficient manner. The proposed system achieves high malware detection rate and promising predictive performance in the family classification, opening the possibility of coping with the use of obfuscation and the growing number of malware.
OriginalsprogEngelsk
Titel2016 International Conference on Computing, Networking and Communications (ICNC)
Antal sider5
ForlagIEEE
Publikationsdatofeb. 2016
ISBN (Elektronisk)978-1-4673-8579-4
DOI
StatusUdgivet - feb. 2016
BegivenhedInternational Conference on Computing, Networking and Communications (ICNC) 2016 - Sheraton Kauai Resort 2440 Hoonani Rd, Poipu Beach Kuaui, HI, USA, Kuaui, USA
Varighed: 15 feb. 201618 feb. 2016
http://www.conf-icnc.org/2016/

Konference

KonferenceInternational Conference on Computing, Networking and Communications (ICNC) 2016
LokationSheraton Kauai Resort 2440 Hoonani Rd, Poipu Beach Kuaui, HI, USA
Land/OmrådeUSA
ByKuaui
Periode15/02/201618/02/2016
Internetadresse

Fingeraftryk

Dyk ned i forskningsemnerne om 'An approach for detection and family classification of malware based on behavioral analysis'. Sammen danner de et unikt fingeraftryk.

Citationsformater