A malware detection scheme based on mining format information.

Malware has become one of the most serious threats to computer information system and the current malware detection technology still has very significant limitations. In this paper, we proposed a malware detection approach by mining format information of PE (portable executable) files. Based on in-d...

Descripción completa

Detalles Bibliográficos
Publicado en:Scientific World Journal pp. 260905 - 260906
Autores principales: Bai, Jinrong, Wang, Junfeng, Zou, Guozhong
Formato: Journal Article
Publicado: Wiley-Blackwell 2014
Acceso en línea:Ver este registro en EBSCOhost
fields @attributes:
  recordID: 1
pdfLink:
plink: https://search.ebscohost.com/login.aspx?direct=true&db=ccm&AN=103832156&site=ehost-live
header:
  @attributes:
    shortDbName: ccm
    uiTerm: 103832156
    longDbName: CINAHL Complete
    uiTag: AN
  controlInfo:
    bkinfo:
    dissinfo:
    jinfo:
      jid:
        1537744X
        1BX5
      jtl: Scientific World Journal
      issn: 1537744X
      maglogo: N
    pubinfo:
      dt: 2014
      pid: 480
      pub: Wiley-Blackwell
      place: Malden, Massachusetts
    artinfo:
      ui:
        103832156
        NLM24991639
        2012636055
        10.1155/2014/260905
        NLM24991639
        PMC4060536
        103832156
      ppf: 260905
      ppct: 1
      formats:
      tig:
        atl: A malware detection scheme based on mining format information.
      aug:
        au:
          Bai, Jinrong
          Wang, Junfeng
          Zou, Guozhong
        affil: College of Computer Science, Sichuan University, Chengdu 610065, China ; School of Information Technology and Engineering, Yuxi Normal University, Yuxi 653100, China.
      sug:
        subj:
          Artificial Intelligence
          Data Mining Methods
          Information Science Methods
          Algorithms
      ab: Malware has become one of the most serious threats to computer information system and the current malware detection technology still has very significant limitations. In this paper, we proposed a malware detection approach by mining format information of PE (portable executable) files. Based on in-depth analysis of the static format information of the PE files, we extracted 197 features from format information of PE files and applied feature selection methods to reduce the dimensionality of the features and achieve acceptable high performance. When the selected features were trained using classification algorithms, the results of our experiments indicate that the accuracy of the top classification algorithm is 99.1% and the value of the AUC is 0.998. We designed three experiments to evaluate the performance of our detection scheme and the ability of detecting unknown and new malware. Although the experimental results of identifying new malware are not perfect, our method is still able to identify 97.6% of new malware with 1.3% false positive rates.
      pubtype: Academic Journal
      doctype: Journal Article
      ougenre: Article
    language: English
    refInfo:
    holdings:
      @attributes:
        islocal: N