Return
Deriving common malware behavior through graph clustering
DOI:10.1016/j.cose.2013.09.006.png)
Abstract
En 中文
Detection of malicious software (malware) continues to be a problem as hackers devise new ways to evade available methods. The proliferation of malware and malware variants requires new advanced methods to detect them. This paper proposes a method to construct a common behavioral graph representing the execution behavior of a family of malware instances. The method generates one common behavioral graph by clustering a set of individual behavioral graphs, which represent kernel objects and their attributes based on system call traces. The resulting common behavioral graph has a common path, called HotPath, which is observed in all the malware instances in the same family. The proposed method shows high detection rates and false positive rates close to 0%. The derived common behavioral graph is highly scalable regardless of new instances added. It is also robust against system call attacks. (C) 2013 Elsevier Ltd. All rights reserved.
Keywords:
Malware
Dynamic analysis
Graph clustering
Intrusion detection
Virtualization
Journal
C
IF:
5.4
Papers:
4.6K
Citations:
1.4W

