Title :
Malicious Executables Classification Based on Behavioral Factor Analysis
Author :
Zhao, HengLi ; Xu, Ming ; Zheng, Ning ; Yao, Jingjing ; Qiang Ho
Author_Institution :
Inst. of Comput. Applic. Technol., HangZhou DianZi Univ., Hangzhou, China
Abstract :
Malware is an increasingly important problem that threatens the security of computer systems. The new concept of cloud security require rapid and automated detection and classification of malicious software. In this paper,we propose a behavior-based automated classification method. Depends on behavioral analysis we characterize malware behavioral profile in a trace report. This report contains the status change caused by the executable and event which are transfered from corresponding Win32 API calls and their certain parameters, we extract behaviour unit strings as features which reflect different malware families behavioral patterns. These features vector space servered as input to the SVM. We use string similarity and information gain to reduce the dimension of feature space. Comparative experiments with a real world data set of malicious executables shows that our proposed method can classify malware into different malware families with higher accuracy and efficiency.
Keywords :
application program interfaces; invasive software; pattern classification; program diagnostics; statistical analysis; support vector machines; SVM; Win32 API calls; behavior based automated classification method; behavioral factor analysis; behaviour unit strings; cloud security; computer systems security; dimension reduction; information gain; malicious executables classification; malware families behavioral patterns; program trace report; Clouds; Computer applications; Computer security; Computer worms; Data mining; Data security; Electronic learning; Electronic mail; Support vector machine classification; Support vector machines; behaviour unit model; malware behaviors; malware classification; reducing dimensions;
Conference_Titel :
e-Education, e-Business, e-Management, and e-Learning, 2010. IC4E '10. International Conference on
Conference_Location :
Sanya
Print_ISBN :
978-1-4244-5680-2
Electronic_ISBN :
978-1-4244-5681-9
DOI :
10.1109/IC4E.2010.78