A Malware Variant Detection Method Based on Byte Randomness Test

被引:5
|
作者
Qi, Shuhui [1 ]
Xu, Ming [1 ]
Zheng, Ning [1 ]
机构
[1] Hangzhou Dianzi Univ, Internet & Network Secur Lab, Inst Comp Sci, Hangzhou, Zhejiang, Peoples R China
关键词
instruction sequences; byte randomness profile (BRP); feature vector; SSD; COS;
D O I
10.4304/jcp.8.10.2469-2477
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
Malware variants, referring to the different members in the same malware family, are generally produced by simply modifying the existing malwares in order to avoid being detected by the traditional signaturebased methods. The mass of malware variants has brought great difficulties to detect malicious code. In this paper, a malware variants detection method based on byte randomness tests is proposed. The bytes distribution value of the instruction sequences obtained from randomness tests, named as the byte randomness profiles, can preserves enough local detail about program, so it can be used as feature vector to represent malware in a distinctive manner. Moreover, the sum of squares distance (SSD) and the cosine similarity (COS) are used to measure the distinctiveness between two malwares. Experimental results show that the proposed method provides a fast and effective way to detect variants of known malware families.
引用
收藏
页码:2469 / 2477
页数:9
相关论文
共 50 条
  • [1] BHMDC: A byte and hex n-gram based malware detection and classification method
    Tang, Yonghe
    Qi, Xuyan
    Jing, Jing
    Liu, Chunling
    Dong, Weiyu
    [J]. COMPUTERS & SECURITY, 2023, 128
  • [2] Byte-Level Function-Associated Method for Malware Detection
    Hao, Jingwei
    Luo, Senlin
    Pan, Limin
    [J]. Computer Systems Science and Engineering, 2023, 46 (01): : 719 - 734
  • [3] Research on Malware Variant Detection Method Based on Deep Neural Network
    Xing Jianhua
    Si Jing
    Zhang Yongjing
    Li Wei
    Zheng Yuning
    [J]. 2021 IEEE 5TH INTERNATIONAL CONFERENCE ON CRYPTOGRAPHY, SECURITY AND PRIVACY (ICCSP), 2021, : 144 - 147
  • [4] IoT-Malware Detection Based on Byte Sequences of Executable Files
    Wan, Tzu-Ling
    Ban, Tao
    Lee, Yen-Ting
    Cheng, Shin-Ming
    Isawa, Ryoichi
    Takahashi, Takeshi
    Inoue, Daisuke
    [J]. 2020 15TH ASIA JOINT CONFERENCE ON INFORMATION SECURITY (ASIAJCIS 2020), 2020, : 143 - 150
  • [5] Research on the Construction of Malware Variant Datasets and Their Detection Method
    Lu, Faming
    Cai, Zhaoyang
    Lin, Zedong
    Bao, Yunxia
    Tang, Mengfan
    [J]. APPLIED SCIENCES-BASEL, 2022, 12 (15):
  • [6] An Android Malware Detection Method Based on Chi-Squared Test
    Liu, Ya-Shu
    Wang, Zhi-Hai
    Li, Jing-Wei
    Zhao, Xuan
    Wen, Wei-Ping
    [J]. Beijing Ligong Daxue Xuebao/Transaction of Beijing Institute of Technology, 2019, 39 (03): : 290 - 294
  • [7] Multi-Head Attention Based Malware Detection with Byte-Level Representation
    Thai Vu Nguyen
    Hoang, Duc N. M.
    Long Bao Le
    [J]. 2024 IEEE WIRELESS COMMUNICATIONS AND NETWORKING CONFERENCE, WCNC 2024, 2024,
  • [8] Control Flow-Based Malware Variant Detection
    Cesare, Silvio
    Xiang, Yang
    Zhou, Wanlei
    [J]. IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2014, 11 (04) : 304 - 317
  • [9] File-level malware detection using byte streams
    Young-Seob Jeong
    Medard Edmund Mswahili
    Ah Reum Kang
    [J]. Scientific Reports, 13
  • [10] File-level malware detection using byte streams
    Jeong, Young-Seob
    Mswahili, Medard Edmund
    Kang, Ah Reum
    [J]. SCIENTIFIC REPORTS, 2023, 13 (01)