Structural Classification and Similarity Measurement of Malware

被引:4
|
作者
Shi, Hongbo [1 ]
Hamagami, Tomoki [2 ]
Yoshioka, Katsunari [2 ]
Xu, Haoyuan [3 ]
Tobe, Kazuhiro [4 ]
Goto, Shigeki [4 ]
机构
[1] Tokyo Metropolitan Univ, Lib & Informat Acad Ctr, Hachioji, Tokyo 1920397, Japan
[2] Yokohama Natl Univ, Div Elect & Comp Engn, Fac Engn, Hodogaya Ku, Yokohama, Kanagawa 2408501, Japan
[3] Yokohama Natl Univ, Informat Technol Serv Ctr, Hodogaya Ku, Yokohama, Kanagawa 2408501, Japan
[4] Waseda Univ, Grad Sch Fundamental Sci & Engn, Fac Sci & Engn, Shinjuku Ku, Tokyo 1698555, Japan
关键词
malware; classification; dynamic link library; GHSOM; tree structure; relationship;
D O I
10.1002/tee.22018
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
This paper proposes a new lightweight method that utilizes the growing hierarchical self-organizing map (GHSOM) for malware detection and structural classification. It also shows a new method for measuring the structural similarity between classes. A dynamic link library (DLL) file is an executable file used in the Windows operating system that allows applications to share codes and other resources to perform particular tasks. In this paper, we classify different malware by the data mining of the DLL files used by the malware. Since the malware families are evolving quickly, they present many new problems, such as how to link them to other existing malware families. The experiment shows that our GHSOM-based structural classification can solve these issues and generate a malware classification tree according to the similarity of malware families. (c) 2014 Institute of Electrical Engineers of Japan. Published by John Wiley & Sons, Inc.
引用
收藏
页码:621 / 632
页数:12
相关论文
共 50 条
  • [31] EntropyVis: Malware Classification
    Ren, Zhuojun
    Chen, Guang
    [J]. 2017 10TH INTERNATIONAL CONGRESS ON IMAGE AND SIGNAL PROCESSING, BIOMEDICAL ENGINEERING AND INFORMATICS (CISP-BMEI), 2017,
  • [32] Variant: A Malware Similarity Testing Framework
    Upchurch, Jason
    Zhou, Xiaobo
    [J]. 2015 10TH INTERNATIONAL CONFERENCE ON MALICIOUS AND UNWANTED SOFTWARE (MALWARE), 2015, : 31 - 39
  • [33] Evolved Similarity Techniques in Malware Analysis
    Black, Paul
    Gondal, Iqbal
    Vamplew, Peter
    Lakhotia, Arun
    [J]. 2019 18TH IEEE INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS/13TH IEEE INTERNATIONAL CONFERENCE ON BIG DATA SCIENCE AND ENGINEERING (TRUSTCOM/BIGDATASE 2019), 2019, : 404 - 409
  • [34] Clustering for malware classification
    Pai S.
    Troia F.D.
    Visaggio C.A.
    Austin T.H.
    Stamp M.
    [J]. Journal of Computer Virology and Hacking Techniques, 2017, 13 (2) : 95 - 107
  • [35] Detecting Malware with Similarity to Android applications
    Park, Wonjoo
    Kim, Sun-joong
    Ryu, Won
    [J]. 2015 INTERNATIONAL CONFERENCE ON ICT CONVERGENCE (ICTC), 2015, : 1249 - 1251
  • [36] Structural and Semantic Similarity Measurement of UML Sequence Diagrams
    Siahaan, Daniel
    Desnelita, Yenny
    Gustientiedina
    Sunarti
    [J]. PROCEEDINGS OF 2017 11TH INTERNATIONAL CONFERENCE ON INFORMATION & COMMUNICATION TECHNOLOGY AND SYSTEMS (ICTS), 2017, : 227 - 233
  • [37] A STRUCTURAL AND SEMANTIC APPROACH TO SIMILARITY MEASUREMENT OF LOGISTICS PROCESSES
    Yahya, Bernardo Nugroho
    Bae, Hyerim
    Bae, Joonsoo
    [J]. INTERNATIONAL JOURNAL OF INDUSTRIAL ENGINEERING-THEORY APPLICATIONS AND PRACTICE, 2013, 20 (1-2): : 47 - 59
  • [38] Malware classification using a byte-granularity feature based on structural entropy
    Paik, Joon-Young
    Jin, Rize
    Cho, Eun-Sun
    [J]. COMPUTATIONAL INTELLIGENCE, 2022, 38 (04) : 1536 - 1558
  • [39] A Malware Classification Method Based on Generic Malware Information
    Choi, Jiyeon
    Kim, HeeSeok
    Choi, Jangwon
    Song, Jungsuk
    [J]. NEURAL INFORMATION PROCESSING, PT II, 2015, 9490 : 329 - 336
  • [40] Malware-on-the-Brain: Illuminating Malware Byte Codes With Images for Malware Classification
    Zhong, Fangtian
    Chen, Zekai
    Xu, Minghui
    Zhang, Guoming
    Yu, Dongxiao
    Cheng, Xiuzhen
    [J]. IEEE TRANSACTIONS ON COMPUTERS, 2023, 72 (02) : 438 - 451