返回
Scalable Detection of Server-Side Polymorphic Malware
DOI:10.1016/j.knosys.2018.05.024.png)
摘要
En 中文
Server-side polymorphism is used by malware distributors in order to evade detection by anti-virus (AV) scanners. It is difficult for traditional AVs to detect this type of malware because the transformation code is not visible for security analysis. Using a tera-scale dataset consisting of antivirus telemetry reports pertaining to more than half a billion files, we conduct what is, to the best of our knowledge, the most wide-scale analysis of the properties of web-borne polymorphic malware done to date. We cluster the files population based on their locality-sensitive hash (LSH) values and analyze the resulting LSH clusters. Using ground truth labels, we identify benign and malicious clusters and analyse the differences between them in terms of the distributions of cluster-size, file download numbers and activity period, and in terms of their web domain utilization patterns. The results of this analysis are then leveraged for devising SPADE a scalable Server-side Polymorphic mAlware DEtector that provides high-quality detection of both malicious files and malicious web domains.
Keyword:
Malware Detection
Server-Side Polymorphism
Locality-Sensitive Hashing
AI总结
对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。
期刊
K
IF:
7.6
论文数:
1.2W
被引数:
4.5W
机构
引用论文
A set of robust fluorescent peptide probes for quantification of Cu(ii) binding affinities in the micromolar to femtomolar range
Metallomics
IF0

