Fast Malware Classification using Counting Bloom Filter

  • Kang, BooJong
  • Kim, Hye Seon
  • Kim, Taeguen
  • Kwon, Heejun
  • Im, Eul Gyu
Citations

WEB OF SCIENCE

1
Citations

SCOPUS

1

초록

As attackers make variants of existing malware, it is possible to detect unknown malware by using already-known malware's information. Control Flow Graphs (CFGs) have been used in malware analysis but the graph isomorphism problem is well-known as one of the most difficult problem to solve. In this paper, we proposed a new fast method which can detect malware binaries using CFGs by abstracting common characteristics of malware families. Our method also uses Counting Bloom Filter to find approximate solution of the graph isomorphism problem. The experimental results showed that processing overhead of our proposed method is much lower than n-gram based methods.

키워드

Network securityMalware analysisControl flow graphCounting bloom filter
제목
Fast Malware Classification using Counting Bloom Filter
저자
Kang, BooJongKim, Hye SeonKim, TaeguenKwon, HeejunIm, Eul Gyu
발행일
2012-07
유형
Article
저널명
Information
15
7
페이지
2879 ~ 2892