AMAL: High-fidelity, behavior-based automated malware analysis and classification

被引:128
|
作者
Mohaisen, Aziz [1 ]
Alrawi, Omar [2 ]
Mohaisen, Manar [3 ]
机构
[1] Verisign Labs, Bozeman, MT USA
[2] Qatar Fdn, QCRI, Doha, Qatar
[3] Korea Tech, Cheonan, South Korea
关键词
Malware; Classification; Automatic analysis; Clustering; Machine learning; Dynamic analysis;
D O I
10.1016/j.cose.2015.04.001
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
This paper introduces AMAL, an automated and behavior-based malware analysis and labeling system that addresses shortcomings of the existing systems. AMAL consists of two sub-systems, AutoMal and MaLabel. AutoMal provides tools to collect low granularity behavioral artifacts that characterize malware usage of the file system, memory, network, and registry, and does that by running malware samples in virtualized environments. On the other hand, MaLabel uses those artifacts to create representative features, use them for building classifiers trained by manually vetted training samples, and use those classifiers to classify malware samples into families similar in behavior. AutoMal also enables unsupervised learning, by implementing multiple clustering algorithms for samples grouping. An evaluation of both AutoMal and MaLabel based on medium-scale (4000 samples) and large-scale datasets (more than 115,000 samples) collected and analyzed by AutoMal over 13 months shows AMAL's effectiveness in accurately characterizing, classifying, and grouping malware samples. MaLabel achieves a precision of 99.5% and recall of 99.6% for certain families' classification, and more than 98% of precision and recall for unsupervised clustering. Several benchmarks, cost estimates and measurements highlight the merits of AMAL. (C) 2015 Elsevier Ltd. All rights reserved.
引用
收藏
页码:251 / 266
页数:16
相关论文
共 50 条
  • [21] A Design of Network Behavior-Based Malware Detection System for Android
    Qi, Yincheng
    Cao, Mingjing
    Zhang, Can
    Wu, Ruping
    [J]. ALGORITHMS AND ARCHITECTURES FOR PARALLEL PROCESSING, ICA3PP 2014, PT II, 2014, 8631 : 590 - 600
  • [22] Detecting Metamorphic Malware by Using Behavior-based Aggregated Signature
    Qu, Yanzhen
    Hughes, Kelly
    [J]. 2013 WORLD CONGRESS ON INTERNET SECURITY (WORLDCIS), 2013, : 13 - 18
  • [23] Behavior-based Speciation in Classification with NeuroEvolution
    Papavasileiou, Evgenia
    Cornelis, Jan
    Jansen, Bart
    [J]. 2020 IEEE CONGRESS ON EVOLUTIONARY COMPUTATION (CEC), 2020,
  • [24] An Efficient Common Substrings Algorithm for On-the-Fly Behavior-Based Malware Detection and Analysis
    Acosta, Jaime C.
    Mendoza, Humberto
    Medina, Brenda G.
    [J]. 2012 IEEE MILITARY COMMUNICATIONS CONFERENCE (MILCOM 2012), 2012,
  • [25] pBMDS: A Behavior-based Malware Detection System for Cellphone Devices
    Xie, Liang
    Zhang, Xinwen
    Seifert, Jean-Pierre
    Zhu, Sencun
    [J]. WISEC 10: PROCEEDINGS ON THE THIRD ACM CONFERENCE ON WIRELESS NETWORK SECURITY, 2010, : 37 - 48
  • [26] Generating Behavior-based Malware Detection Models with Genetic Programming
    Wuechner, Tobias
    Ochoa, Martin
    Lovat, Enrico
    Pretschner, Alexander
    [J]. 2016 14TH ANNUAL CONFERENCE ON PRIVACY, SECURITY AND TRUST (PST), 2016,
  • [27] Intelligent Mobile Malware Detection via Behavior-based Features
    Liu, Yihong
    Huang, Xiaokun
    [J]. INTERNATIONAL CONFERENCE ON ELECTRICAL AND CONTROL ENGINEERING (ICECE 2015), 2015, : 402 - 407
  • [28] Malware Classification Based on Dynamic Behavior
    Cabau, George
    Buhu, Magda
    Oprisa, Ciprian
    [J]. PROCEEDINGS OF 2016 18TH INTERNATIONAL SYMPOSIUM ON SYMBOLIC AND NUMERIC ALGORITHMS FOR SCIENTIFIC COMPUTING (SYNASC), 2016, : 315 - 318
  • [29] Leveraging Compression-Based Graph Mining for Behavior-Based Malware Detection
    Wuchner, Tobias
    Cislak, Aleksander
    Ochoa, Martin
    Pretschner, Alexander
    [J]. IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2019, 16 (01) : 99 - 112
  • [30] FEM-based High-fidelity Solar Radiation Pressure Analysis
    Matsumoto, Jun
    Ono, Go
    Chujo, Toshihiro
    Akatsuka, Kosuke
    Tsuda, Yuichi
    [J]. TRANSACTIONS OF THE JAPAN SOCIETY FOR AERONAUTICAL AND SPACE SCIENCES, 2017, 60 (05) : 276 - 283