返回
Control Flow-Based Malware Variant Detection
DOI:10.1109/TDSC.2013.40.png)
摘要
En 中文
Static detection of malware variants plays an important role in system security and control flow has been shown as an effective characteristic that represents polymorphic malware. In our research, we propose a similarity search of malware to detect these variants using novel distance metrics. We describe a malware signature by the set of control flowgraphs the malware contains. We use a distance metric based on the distance between feature vectors of string-based signatures. The feature vector is a decomposition of the set of graphs into either fixed size k-subgraphs, or q-gram strings of the high-level source after decompilation. We use this distance metric to perform pre-filtering. We also propose a more effective but less computationally efficient distance metric based on the minimum matching distance. The minimum matching distance uses the string edit distances between programs' decompiled flowgraphs, and the linear sum assignment problem to construct a minimum sum weight matching between two sets of graphs. We implement the distance metrics in a complete malware variant detection system. The evaluation shows that our approach is highly effective in terms of a limited false positive rate and our system detects more malware variants when compared to the detection rates of other algorithms.
Keyword:
Computer security
malware classification
static analysis
control flow
structuring
decompilation
AI总结
对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。
期刊
IF:
7.5
论文数:
2.5K
被引数:
9.6K
机构
引用论文
Hydrothermal preparation and low temperature magnetic properties of TbOOH, DyOOH, HoOOH, ErOOH, and YbOOHTbOOH,DyOOH,HoOOH,ErOOH和YbOOH的水热制备和低温磁性

