Return
Control flow-based opcode behavior analysis for Malware detection
DOI:10.1016/j.cose.2014.04.003.png)
Abstract
En 中文
Opcode sequences from decompiled executables have been employed to detect malware. Currently, opcode sequences are extracted using text-based methods, and the limitation of this method is that the extracted opcode sequences cannot represent the true behaviors of an executable. To solve this issue, we present a control flow-based method to extract executable opcode behaviors. The behaviors extracted by this method can fully represent the behavior characteristics of an executable. To verify the efficiency of control flow-based behaviors, we perform a comparative study of the two types of opcode behavior analysis methods. The experimental results indicate that the proposed control flow-based method has a higher overall accuracy and a lower false positive rate. (C) 2014 Elsevier Ltd. All rights reserved.
Keywords:
Opcode sequence
Malicious code detection
Control flow graph
Machine learning
Classification
Security
Journal
C
IF:
5.4
Papers:
4.6K
Citations:
1.4W
Organization
Cited Papers
Problems of scientific methodology related to placebo control in Qigong studies: A systematic review
A fast malware detection algorithm based on objective-oriented association mining
COMPUTERS & SECURITY
IF5.4
Allosteric Regulation in Phosphofructokinase from the Extreme Thermophile Thermus thermophilus
Biochemistry
IF0

