• DocumentCode
    591074
  • Title

    Toward extracting malware features for classification using static and dynamic analysis

  • Author

    Young Han Choi ; Byoung Jin Han ; Byung Chul Bae ; Hyung Geun Oh ; Ki Wook Sohn

  • Author_Institution
    Attached Inst. of ETRI, Daejeon, South Korea
  • fYear
    2012
  • fDate
    27-29 Aug. 2012
  • Firstpage
    126
  • Lastpage
    129
  • Abstract
    Because of a great many malware, they must be classified into malware family before being analyzed manually. Otherwise, we cannot analyze and handle them in real time. By classifying them, we can analyze only some unknown malwares intensively. In this paper, we propose a framework for malware classification using static and dynamic analysis. We focus on techniques that extract malware features. We name the framework GATTACA(Genome-based ATTACk geneAlogy) from the movie that covers genome of human. We define features of Malware as Mal-DNA(Malware DNA). Mal-DNA includes static, hybrid and dynamic characteristics. In short, GATTACA is the framework for extracting Mal-DNA from malwares and classifying them. GATTACA consists of three components: (1) START(STatic Analyzer using vaRious Techniques) extracts static Mal-DNA of malware. (2) DeBON(Debugging-based Behavior mOnitor and aNalyzer) extracts hybrid and dynamic Mal-DNA of them. (3) CLAM(CLassifier using Mal-DNA) classifies malwares based on Mal-DNA using machine learning. START and DeBON extract Mal-DNA, and CLAM classifies malwares based on Mal-DNA. In this paper, we target on START and DeBON extracting Mal-DAN from malwares.
  • Keywords
    invasive software; learning (artificial intelligence); pattern classification; program debugging; program diagnostics; CLAM component; DeBON component; GATTACA framework; START component; classifier using mal-DNA; debugging-based behavior monitor and analyzer; dynamic analysis; genome-based attack genealogy; machine learning; malware DNA; malware analysis; malware classification; malware feature extraction; static analysis; static analyzer using various techniques; Bioinformatics; DNA; Feature extraction; Genomics; Kernel; Malware; Monitoring; Feature Extraction; Malware Classification;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computing and Networking Technology (ICCNT), 2012 8th International Conference on
  • Conference_Location
    Gueongju
  • Print_ISBN
    978-1-4673-1326-1
  • Type

    conf

  • Filename
    6418637