AMAL: High-fidelity, behavior-based automated malware analysis and classification

被引:128
|
作者
Mohaisen, Aziz [1 ]
Alrawi, Omar [2 ]
Mohaisen, Manar [3 ]
机构
[1] Verisign Labs, Bozeman, MT USA
[2] Qatar Fdn, QCRI, Doha, Qatar
[3] Korea Tech, Cheonan, South Korea
关键词
Malware; Classification; Automatic analysis; Clustering; Machine learning; Dynamic analysis;
D O I
10.1016/j.cose.2015.04.001
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
This paper introduces AMAL, an automated and behavior-based malware analysis and labeling system that addresses shortcomings of the existing systems. AMAL consists of two sub-systems, AutoMal and MaLabel. AutoMal provides tools to collect low granularity behavioral artifacts that characterize malware usage of the file system, memory, network, and registry, and does that by running malware samples in virtualized environments. On the other hand, MaLabel uses those artifacts to create representative features, use them for building classifiers trained by manually vetted training samples, and use those classifiers to classify malware samples into families similar in behavior. AutoMal also enables unsupervised learning, by implementing multiple clustering algorithms for samples grouping. An evaluation of both AutoMal and MaLabel based on medium-scale (4000 samples) and large-scale datasets (more than 115,000 samples) collected and analyzed by AutoMal over 13 months shows AMAL's effectiveness in accurately characterizing, classifying, and grouping malware samples. MaLabel achieves a precision of 99.5% and recall of 99.6% for certain families' classification, and more than 98% of precision and recall for unsupervised clustering. Several benchmarks, cost estimates and measurements highlight the merits of AMAL. (C) 2015 Elsevier Ltd. All rights reserved.
引用
收藏
页码:251 / 266
页数:16
相关论文
共 50 条
  • [41] Intelligent Behavior-Based Malware Detection System on Cloud Computing Environment
    Aslan, Omer
    Ozkan-Okay, Merve
    Gupta, Deepti
    [J]. IEEE Access, 2021, 9 : 83252 - 83271
  • [42] Traffic Behavior-based Device Type Classification
    Takasaki, Chikako
    Korikawa, Tomohiro
    Hattori, Kyota
    Ohwada, Hidenari
    [J]. 2023 INTERNATIONAL CONFERENCE ON COMPUTING, NETWORKING AND COMMUNICATIONS, ICNC, 2023, : 353 - 357
  • [43] An Android Behavior-Based Malware Detection Method using Machine Learning
    Chang, Wei-Ling
    Sun, Hung-Min
    Wu, Wei
    [J]. 2016 IEEE INTERNATIONAL CONFERENCE ON SIGNAL PROCESSING, COMMUNICATIONS AND COMPUTING (ICSPCC), 2016,
  • [44] An automated force field optimization tool for high-fidelity lipid models
    Antila, Hanne S.
    Miettinen, Markus S.
    [J]. BIOPHYSICAL JOURNAL, 2022, 121 (03) : 309A - 309A
  • [45] HIGH-FIDELITY SURFACE PROFILOMETRY Automated Fiber Placement Inspection: Enabling Paradigm Shift in Quality Control Towards High-Fidelity Surface Profilometry
    Roy, Steven
    Palardy-Sim, Marc
    Rivard, Maxime
    Lamouche, Guy
    Padioleau, Christian
    Yousefpour, Ali
    Lund, Gil
    Zupan, Matt
    Klakken, Marcus
    Albers, Steve
    Harper, Robert
    [J]. SAMPE JOURNAL, 2022, 58 (03) : 17 - 27
  • [46] Malware Classification Based on the Behavior Analysis and Back Propagation Neural Network
    Pan, Zhi-Peng
    Feng, Chao
    Tang, Chao-Jing
    [J]. 3RD ANNUAL INTERNATIONAL CONFERENCE ON INFORMATION TECHNOLOGY AND APPLICATIONS (ITA 2016), 2016, 7
  • [47] Automated vehicle's behavior decision making using deep reinforcement learning and high-fidelity simulation environment
    Ye, Yingjun
    Zhang, Xiaohui
    Sun, Jian
    [J]. TRANSPORTATION RESEARCH PART C-EMERGING TECHNOLOGIES, 2019, 107 : 155 - 170
  • [48] CrashTest: A Fast High-Fidelity FPGA-Based Resiliency Analysis Framework
    Pellegrini, Andrea
    Constantinides, Kypros
    Zhang, Dan
    Sudhakar, Shobana
    Bertacco, Valeria
    Austin, Todd
    [J]. 2008 IEEE INTERNATIONAL CONFERENCE ON COMPUTER DESIGN, 2008, : 363 - 370
  • [49] High-Fidelity Induction Motor Simulation Model Based on Finite Element Analysis
    Lee, Joon-Hee
    Kwon, Yong-Cheol
    Sul, Seung-Ki
    [J]. IEEE TRANSACTIONS ON INDUSTRIAL ELECTRONICS, 2022, 69 (10) : 9872 - 9883
  • [50] A Behavior-based Mobile Malware Detection Model in Software-Defined Networking
    Tri-Hai Nguyen
    Yoo, Myungsik
    [J]. 2017 INTERNATIONAL CONFERENCE ON INFORMATION SCIENCE AND COMMUNICATIONS TECHNOLOGIES (ICISCT) - APPLICATIONS, TRENDS AND OPPORTUNITIES, 2017,