DocumentCode :
142218
Title :
Proactive malware collection and classification system: How to collect and classify useful malware samples?
Author :
Tseng, Chinyang Henry ; Shiahuey Wang ; Sheng-Chao Wang ; Tong-Ying Juang
Author_Institution :
Dept. of Comput. Sci. & Inf. Eng., Nat. Taipei Univ., Taipei, Taiwan
Volume :
3
fYear :
2014
fDate :
26-28 April 2014
Firstpage :
1846
Lastpage :
1849
Abstract :
To understand malware behaviors, collecting and classifying malware samples is a critical issue for system security researchers. This paper aims to develop Proactive Malware Collection and Classification System (PMCCS), which consists of Proactive Malware Collection Unit (PMCU) and Automatic Malware Classification Unit (AMCU). To collect useful samples, PMCU uses P2P software actively search suspicious samples, such as software crack tools. During a 3-year period, PMCU has collected 42300 samples. To automatically classify useful samples, AMCU uploads suspicious samples to VirusTotal, a free online virus scanner. Based on VirusTotal scanning results, 11600 suspicious samples have been alerted at least once by AntiVirusWare (AVW) and 70% of these samples are Trojans and Virus tools, which are usually threatening malwares. Moreover, these suspicious 11600 samples are classified into: Blacklist with high suspiciousness; Ambitious list with moderate suspiciousness; Whitelist with low suspiciousness. Blacklist can be used to evaluate the performance of AVW based on False Negative (FN). On the other hand, Whitelist can be used to evaluate the performance of AVW based on False Positive (FP). From Blacklist and Whitelist, AMCU selects useful malwares, which triggering high counts of FN and FP against AVW.
Keywords :
computer viruses; pattern classification; peer-to-peer computing; AMCU; AVW; P2P software; PMCCS; PMCU; Trojans tools; antivirusware; automatic malware classification unit; blacklist; false negative; false positive; proactive malware collection unit; proactive malware collection-and-classification system; system security; virus scanner; virus tools; virustotal; whitelist; Databases; Grippers; Software; Testing; Trojan horses; AntiVirusWare (AVW); Blacklist; False negative (FP); False positive (FP); Malware sample; Whitelist;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Information Science, Electronics and Electrical Engineering (ISEEE), 2014 International Conference on
Conference_Location :
Sapporo
Print_ISBN :
978-1-4799-3196-5
Type :
conf
DOI :
10.1109/InfoSEEE.2014.6946241
Filename :
6946241
Link To Document :
بازگشت