Title :
Malware detection and classification based on extraction of API sequences
Author :
Uppal, Dolly ; Sinha, Roopak ; Mehra, Vishakha ; Jain, Vinesh
Author_Institution :
Dept. of Comput. Eng. & Inf. Technol., Gov. Eng. Coll., Ajmer, India
Abstract :
With the substantial growth of IT sector in the 21st century, the need for system security has also become inevitable. While the developments in the IT sector have innumerable advantages but attacks on websites and computer systems are also increasing relatively. One such attack is zero day malware attack which poses a great challenge for the security testers. The malware pen testers can use bypass techniques like Compression, Code obfuscation and Encryption techniques to easily deceive present day Antivirus Scanners. This paper elucidates a novel malware identification approach based on extracting unique aspects of API sequences. The proposed feature selection method based on N grams and odds ratio selection, capture unique and distinct API sequences from the extracted API calls thereby increasing classification accuracy. Next a model is built by the classification algorithms using active machine learning techniques to categorize malicious and benign files.
Keywords :
application program interfaces; invasive software; learning (artificial intelligence); pattern classification; API sequences extraction; IT sector; N grams; Websites; active machine learning techniques; antivirus scanners; benign files; bypass techniques; code obfuscation; computer systems; encryption techniques; malicious files; malware classification; malware detection; malware pen testers; odds ratio selection; security testers; zero day malware attack; Accuracy; Classification algorithms; Feature extraction; Machine learning algorithms; Malware; Software; API call gram; API sequence; Malware;
Conference_Titel :
Advances in Computing, Communications and Informatics (ICACCI, 2014 International Conference on
Conference_Location :
New Delhi
Print_ISBN :
978-1-4799-3078-4
DOI :
10.1109/ICACCI.2014.6968547