A Malware Variant Detection Method Based on Byte Randomness Test

被引:5
|
作者
Qi, Shuhui [1 ]
Xu, Ming [1 ]
Zheng, Ning [1 ]
机构
[1] Hangzhou Dianzi Univ, Internet & Network Secur Lab, Inst Comp Sci, Hangzhou, Zhejiang, Peoples R China
关键词
instruction sequences; byte randomness profile (BRP); feature vector; SSD; COS;
D O I
10.4304/jcp.8.10.2469-2477
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
Malware variants, referring to the different members in the same malware family, are generally produced by simply modifying the existing malwares in order to avoid being detected by the traditional signaturebased methods. The mass of malware variants has brought great difficulties to detect malicious code. In this paper, a malware variants detection method based on byte randomness tests is proposed. The bytes distribution value of the instruction sequences obtained from randomness tests, named as the byte randomness profiles, can preserves enough local detail about program, so it can be used as feature vector to represent malware in a distinctive manner. Moreover, the sum of squares distance (SSD) and the cosine similarity (COS) are used to measure the distinctiveness between two malwares. Experimental results show that the proposed method provides a fast and effective way to detect variants of known malware families.
引用
收藏
页码:2469 / 2477
页数:9
相关论文
共 50 条
  • [11] Byte Level n-Gram Analysis for Malware Detection
    Jain, Sacbin
    Meena, Yogesb Kumar
    [J]. COMPUTER NETWORKS AND INTELLIGENT COMPUTING, 2011, 157 : 51 - 59
  • [12] Malware Detection Using Byte Streams of Different File Formats
    Jeong, Young-Seob
    Lee, Sang-Min
    Kim, Jong-Hyun
    Woo, Jiyoung
    Kang, Ah Reum
    [J]. IEEE ACCESS, 2022, 10 : 51041 - 51047
  • [13] Malware Detection Method Based on Visualization
    Xie, Nannan
    Liang, Haoxiang
    Mu, Linyang
    Zhang, Chuanxue
    [J]. ALGORITHMS AND ARCHITECTURES FOR PARALLEL PROCESSING, ICA3PP 2023, PT VI, 2024, 14492 : 252 - 264
  • [14] Malware Detection on Byte Streams of Hangul Word Processor Files
    Jeong, Young-Seob
    Woo, Jiyoung
    Kang, Ah Reum
    [J]. APPLIED SCIENCES-BASEL, 2019, 9 (23):
  • [15] Malware classification based on double byte feature encoding
    Li, Lin
    Ding, Ying
    Li, Bo
    Qiao, Mengqing
    Ye, Biao
    [J]. ALEXANDRIA ENGINEERING JOURNAL, 2022, 61 (01) : 91 - 99
  • [16] Detection of encrypted executable files based on entropy analysis to determine the randomness measure of byte sequences
    Alekseev I.V.
    Platonov V.V.
    [J]. Automatic Control and Computer Sciences, 2017, 51 (8) : 915 - 920
  • [17] Clustering based opcode graph generation for malware variant detection
    Wai, Fok Kar
    Thing, Vrizlynn L. L.
    [J]. 2021 18TH INTERNATIONAL CONFERENCE ON PRIVACY, SECURITY AND TRUST (PST), 2021,
  • [18] Malware Variant Detection Based on Decomposed Deep Convolutional Network
    Mai, Jianbin
    Cao, Chunjie
    Shi, Fangfei
    Chen, Xiaoqing
    [J]. 2021 IEEE 6TH INTERNATIONAL CONFERENCE ON BIG DATA ANALYTICS (ICBDA 2021), 2021, : 333 - 338
  • [19] Learning Latent Byte-Level Feature Representation for Malware Detection
    Yousefi-Azar, Mahmood
    Hamey, Len
    Varadharajan, Vijay
    Chen, Shiping
    [J]. NEURAL INFORMATION PROCESSING (ICONIP 2018), PT IV, 2018, 11304 : 568 - 578
  • [20] A Malware and Variant Detection Method Using Function Call Graph Isomorphism
    Bai, Jinrong
    Shi, Qibin
    Mu, Shiguang
    [J]. SECURITY AND COMMUNICATION NETWORKS, 2019, 2019