DocumentCode
3780171
Title
Malfinder: Accelerated malware classification system through filtering on manycore system
Author
Taegyu Kim;Woomin Hwang;Chulmin Kim;Dong-Jae Shin;Ki-Woong Park;Kyu Ho Park
Author_Institution
Korea Advanced Institute of Science and Technology (KAIST), Daejeon, Republic of Korea
fYear
2015
Firstpage
1
Lastpage
10
Abstract
Control flow matching methods have been utilized to detect malware variants. However, as the number of malware variants has soared, it has become harder and harder to detect all malware variants while maintaining high accuracy. Even though many researchers have proposed control flow matching methods, there is still a trade-off between accuracy and performance. To solve this trade-off, we designed Malfinder, a method based on approximate matching, which is accurate but slow. To overcome its low performance, we resolve its performance bottleneck and non-parallelism on three fronts: I-Filter for identical string matching, table division to exclude unnecessary comparisons with some malware and dynamic resource allocation for efficient parallelism. Our performance evaluation shows that the total performance improvement is 280.9 times.
Keywords
"Malware","Databases","Resource management","Parallel processing","Time complexity","Acceleration","Converters"
Publisher
ieee
Conference_Titel
Information Systems Security and Privacy (ICISSP), 2015 International Conference on
Type
conf
Filename
7509924
Link To Document