Behavior-based features model for malware detection

被引:98
|
作者
Galal H.S. [1 ]
Mahdy Y.B. [1 ]
Atiea M.A. [1 ]
机构
[1] Faculty of Computers and Information, Assiut University, Assiut
关键词
Hide Markov Model; Virtual Machine; Heuristic Function; Control Flow Graph; Benign Sample;
D O I
10.1007/s11416-015-0244-0
中图分类号
学科分类号
摘要
The sharing of malicious code libraries and techniques over the Internet has vastly increased the release of new malware variants in an unprecedented rate. Malware variants share similar behaviors yet they have different syntactic structure due to the incorporation of many obfuscation and code change techniques such as polymorphism and metamorphism. The different structure of malware variants poses a serious problem to signature-based detection technique, yet their similar exhibited behaviors and actions can be a remarkable feature to detect them by behavior-based techniques. Malware instances also largely depend on API calls provided by the operating system to achieve their malicious tasks. Therefore, behavior-based detection techniques that utilize API calls are promising for the detection of malware variants. In this paper, we propose a behavior-based features model that describes malicious action exhibited by malware instance. To extract the proposed model, we first perform dynamic analysis on a relatively recent malware dataset inside a controlled virtual environment and capture traces of API calls invoked by malware instances. The traces are then generalized into high-level features we refer to as actions. We assessed the viability of actions by various classification algorithms such as decision tree, random forests, and support vector machine. The experimental results demonstrate that the classifiers attain high accuracy and satisfactory results in the detection of malware variants. © 2015, Springer-Verlag France.
引用
收藏
页码:59 / 67
页数:8
相关论文
共 50 条
  • [1] Intelligent Mobile Malware Detection via Behavior-based Features
    Liu, Yihong
    Huang, Xiaokun
    INTERNATIONAL CONFERENCE ON ELECTRICAL AND CONTROL ENGINEERING (ICECE 2015), 2015, : 402 - 407
  • [2] Lightweight Behavior-Based Malware Detection
    Anisetti, Marco
    Ardagna, Claudio A.
    Bena, Nicola
    Giandomenico, Vincenzo
    Gianini, Gabriele
    MANAGEMENT OF DIGITAL ECOSYSTEMS, MEDES 2023, 2024, 2022 : 237 - 250
  • [3] Behavior-based malware analysis and detection
    Liu, Wu
    Ren, Ping
    Liu, Ke
    Duan, Hai-Xin
    Proceedings - 2011 1st International Workshop on Complexity and Data Mining, IWCDM 2011, 2011, : 39 - 42
  • [4] A BEHAVIOR-BASED APPROACH FOR MALWARE DETECTION
    Mosli, Rayan
    Li, Rui
    Yuan, Bo
    Pan, Yin
    ADVANCES IN DIGITAL FORENSICS XIII, 2017, 511 : 187 - 201
  • [5] Behavior-Based Malware Detection on Mobile Phone
    Dai, Shuaifu
    Liu, Yaxin
    Wang, Tielei
    Wei, Tao
    Zou, Wei
    2010 6TH INTERNATIONAL CONFERENCE ON WIRELESS COMMUNICATIONS NETWORKING AND MOBILE COMPUTING (WICOM), 2010,
  • [6] A Study on The behavior-based Malware Detection Signature
    Oh, Sungtaek
    Go, Woong
    Lee, Taejin
    ADVANCES ON BROAD-BAND WIRELESS COMPUTING, COMMUNICATION AND APPLICATIONS, 2017, 2 : 663 - 670
  • [7] On Behavior-based Detection of Malware on Android Platform
    Yu, Wei
    Zhang, Hanlin
    Ge, Linqiang
    Hardy, Rommie
    2013 IEEE GLOBAL COMMUNICATIONS CONFERENCE (GLOBECOM), 2013, : 814 - 819
  • [8] Shikra: A behavior-based Android malware detection framework
    Ma Zhao-hui
    Chen Zi-hao
    Wang Xin-ming
    Nic Rui-hua
    Zhao Gan-sen
    Wu Jie-chao
    Ren Xue-qi
    2017 INTERNATIONAL CONFERENCE ON GREEN INFORMATICS (ICGI), 2017, : 175 - 184
  • [9] An effective behavior-based Android malware detection system
    Zou, Shihong
    Zhang, Jing
    Lin, Xiaodong
    SECURITY AND COMMUNICATION NETWORKS, 2015, 8 (12) : 2079 - 2089
  • [10] Improved behavior-based malware detection algorithm with AdaBoost
    Cao, Y. (yingcao@stu.xidian.edu.cn), 1600, Science Press (40):