Malware detection method based on attribute similarity
ZHANG Fu-yong
QIN Yong
Abstract:Aiming at the problem that the number of unknown malware has dramatically increased and the existing detection methods can not effectively detect them, a malware detection method based on attribute similarity was proposed. In the proposed method, the sample files were converted into the hexadecimal format, and all n-grams of sample files were extracted. The information gain of each n-gram was calculated, and N n-grams with the maximum information gains were selected as the feature attributes. In addition, the average value of each dimension attribute in malware and normal files was calculated, respectively. The categories of samples to be detected were determined through comparing the attribute similarity of samples to be detected as well as the similarity of avarage attribute values of both malware and normal files. The results reveal that the proposed method is superior to the malware detection method based on n-grams for unknown malware detection.
Keywords:malware detectionattribute similaritynetwork and information securityintrusion detectiondata miningmachine learningunknown malwarestatic analysis
Publication Date:2017-01-01
Online Publishing Date:2025-08-15(First online date of this platform, not the publication date of the document)
Pages:5( 659-663 )
