A malware detection scheme based on mining format information.
Malware has become one of the most serious threats to computer information system and the current malware detection technology still has very significant limitations. In this paper, we proposed a malware detection approach by mining format information of PE (portable executable) files. Based on in-d...
| Publicado en: | Scientific World Journal pp. 260905 - 260906 |
|---|---|
| Autores principales: | , , |
| Formato: | Journal Article |
| Publicado: |
Wiley-Blackwell
2014
|
| Acceso en línea: | Ver este registro en EBSCOhost |
| fields | @attributes: recordID: 1 pdfLink: plink: https://search.ebscohost.com/login.aspx?direct=true&db=ccm&AN=103832156&site=ehost-live header: @attributes: shortDbName: ccm uiTerm: 103832156 longDbName: CINAHL Complete uiTag: AN controlInfo: bkinfo: dissinfo: jinfo: jid: 1537744X 1BX5 jtl: Scientific World Journal issn: 1537744X maglogo: N pubinfo: dt: 2014 pid: 480 pub: Wiley-Blackwell place: Malden, Massachusetts artinfo: ui: 103832156 NLM24991639 2012636055 10.1155/2014/260905 NLM24991639 PMC4060536 103832156 ppf: 260905 ppct: 1 formats: tig: atl: A malware detection scheme based on mining format information. aug: au: Bai, Jinrong Wang, Junfeng Zou, Guozhong affil: College of Computer Science, Sichuan University, Chengdu 610065, China ; School of Information Technology and Engineering, Yuxi Normal University, Yuxi 653100, China. sug: subj: Artificial Intelligence Data Mining Methods Information Science Methods Algorithms ab: Malware has become one of the most serious threats to computer information system and the current malware detection technology still has very significant limitations. In this paper, we proposed a malware detection approach by mining format information of PE (portable executable) files. Based on in-depth analysis of the static format information of the PE files, we extracted 197 features from format information of PE files and applied feature selection methods to reduce the dimensionality of the features and achieve acceptable high performance. When the selected features were trained using classification algorithms, the results of our experiments indicate that the accuracy of the top classification algorithm is 99.1% and the value of the AUC is 0.998. We designed three experiments to evaluate the performance of our detection scheme and the ability of detecting unknown and new malware. Although the experimental results of identifying new malware are not perfect, our method is still able to identify 97.6% of new malware with 1.3% false positive rates. pubtype: Academic Journal doctype: Journal Article ougenre: Article language: English refInfo: holdings: @attributes: islocal: N |
|---|