arrow
Return

Deriving common malware behavior through graph clustering

delete2013-11-01
delete70
PRE
AI
Y
Younghee Park *
D
Douglas S. Reeves
M
Mark Stamp
DOI:10.1016/j.cose.2013.09.006delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Detection of malicious software (malware) continues to be a problem as hackers devise new ways to evade available methods. The proliferation of malware and malware variants requires new advanced methods to detect them. This paper proposes a method to construct a common behavioral graph representing the execution behavior of a family of malware instances. The method generates one common behavioral graph by clustering a set of individual behavioral graphs, which represent kernel objects and their attributes based on system call traces. The resulting common behavioral graph has a common path, called HotPath, which is observed in all the malware instances in the same family. The proposed method shows high detection rates and false positive rates close to 0%. The derived common behavioral graph is highly scalable regardless of new instances added. It is also robust against system call attacks. (C) 2013 Elsevier Ltd. All rights reserved.
Keywords:
Malware
Dynamic analysis
Graph clustering
Intrusion detection
Virtualization

Journal

C
Computers and Security
IF:
5.4
Papers:
4.6K
Citations:
1.4W

Organization

S
San Jose State University
Scholars:
1.3K
Papers: 1.0K
Citations: 15
California State University System cover
California State University System
Scholars:
2.8W
Papers: 2.4W
Citations: 457
N
North Carolina State University
Scholars:
2.6W
Papers: 2.3W
Citations: 3.7W
researcher View more organizations