arrow
Return

Leveraging Compression-Based Graph Mining for Behavior-Based Malware Detection

delete2019-01-01
delete48
PRE
AI
T
Tobias Wüchner *
A
Aleksander Cisłak
M
Martín Ochoa
A
Alexander Pretschner
DOI:10.1109/TDSC.2017.2675881delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Behavior-based detection approaches commonly address the threat of statically obfuscated malware. Such approaches often use graphs to represent process or system behavior and typically employ frequency-based graph mining techniques to extract characteristic patterns from collections of malware graphs. Recent studies in the molecule mining domain suggest that frequency-based graph mining algorithms often perform sub-optimally in finding highly discriminating patterns. We propose a novel malware detection approach that uses so-called compression-based mining on quantitative data flow graphs to derive highly accurate detection models. Our evaluation on a large and diverse malware set shows that our approach outperforms frequency-based detection models in terms of detection effectiveness by more than 600 percent.
Keywords:
Malware detection
quantitative data flow analysis
data mining
graph mining
machine learning
AI Summary

AI Summary

Key information extracted from the uploaded paper, including a brief overview, abstract, background, key highlights, visual analysis, and future outlook.

Journal

IEEE Transactions on Dependable and Secure Computing cover
IEEE Transactions on Dependable and Secure Computing
IF:
7.5
Papers:
2.4K
Citations:
9.6K

Organization

S
singapore university of technology & design
Scholars:
2.8K
Papers: 3.6K
Citations: 5
W
Warsaw University of Technology
Scholars:
8.3K
Papers: 7.2K
Citations: 5.5K
T
Technical University of Munich
Scholars:
5.2W
Papers: 3.9W
Citations: 6.2W
researcher View more organizations