• DocumentCode
    2173610
  • Title

    Malware Detection by Data Mining Techniques Based on Positionally Dependent Features

  • Author

    Komashinskiy, Dmitriy ; Kotenko, Igor

  • Author_Institution
    Comput. Security Res. Group, St.Petersburg Inst. for Inf. & Autom., St. Petersburg, Russia
  • fYear
    2010
  • fDate
    17-19 Feb. 2010
  • Firstpage
    617
  • Lastpage
    623
  • Abstract
    The challenges being thrown to modern world by the need to counteract against malicious software (malware) are going on to increase own importance. This fact stays actual, in spite of obvious great results in improving the efficacy of procedures of malware propagation detection, analysis and updating the bases of signatures and detection rules. The important aspect of this problem is looking for more reliable heuristic detection methods. These methods focus on recognition of new (unknown before) malicious programs which can not be detected by using traditional signature- and rule-based detection techniques, oriented on search for concrete malware samples and families. Virtually, just these heuristic methods provide counteraction against targeted and zero-day attacks, since the rate of detecting such relatively new types of threats by traditional techniques is not enough. The presented paper is devoted to using Data Mining methods for constructing heuristic malware detectors. The approach described below differs from others by focusing on processing static positionally dependent features which consider the specificities of object´s file format of potential malware containers. The paper describes the realization and investigation of the common methodology for design of Data Mining-based malware detectors´ using positionally dependent static information.
  • Keywords
    data mining; digital signatures; invasive software; knowledge based systems; data mining methods; data mining techniques; data mining-based malware detectors; heuristic detection methods; heuristic malware detectors; malicious programs; malicious software; malware detection; malware propagation detection; positionally dependent features; potential malware containers; rule-based detection techniques; signature-based detection techniques; zero-day attacks; Automation; Computer security; Concrete; Containers; Data mining; Design methodology; Detectors; Electronic mail; Informatics; Phase detection; classification; feature selection; malware; positionally dependent features; static and dynamic detection;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Parallel, Distributed and Network-Based Processing (PDP), 2010 18th Euromicro International Conference on
  • Conference_Location
    Pisa
  • ISSN
    1066-6192
  • Print_ISBN
    978-1-4244-5672-7
  • Electronic_ISBN
    1066-6192
  • Type

    conf

  • DOI
    10.1109/PDP.2010.30
  • Filename
    5452410