Automatic clustering of malware variants

2016 IEEE Conference on Intelligence and Security Informatics (ISI)(2016)

引用 13|浏览27
暂无评分
摘要
The emergence of malware creation tools in recent years has facilitated the creation of new variations of existing malware instances. Typically, Anti-Virus companies process new malware instances manually to determine their maliciousness and generate their signatures. However, with the overwhelming number of new malware variants that are created automatically to evade pattern based detection, manual analysis is becoming a bottleneck that hinders the process of responding to new threats. This paper proposes a novel method to automatically cluster malware variants into malware families based on the structured control flow graphs of the malware instances. Our final results demonstrate high effectiveness in terms of accuracy, an average of %94 accuracy, and speed in clustering malware variants.
更多
查看译文
关键词
malware variant automatic clustering,malware creation tools,antivirus companies,malware instances,maliciousness determination,signature generation,pattern based detection,malware families,structured control flow graphs
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要