Malware classification method via binary content comparison

  • Kang, Boojoong
  • Kim, Taekeun
  • Kwon, Heejun
  • Choi, Yangseo
  • Im, Eul Gyu
Citations

SCOPUS

34

초록

With the wide spread uses of the Internet, the number of Internet attacks keeps increasing, and malware is the main cause of most Internet attacks. Malware is used by attackers to infect normal users' computers and to acquire private information as well as to attack other machines. The number of new malware and variants of malware is increasing every year because the automated tools allow attackers to generate the new malware or their variants easily. Therefore, performance improvement of the malware analysis is critical to prevent malware from spreading rapidly and to mitigate damages to users. In this paper, we proposed a new malware classification method by analyzing similarities of malware. Our method analyzes a small part of malware to reduce analysis overheads, and experimental results showed that our approach can effectively classify malware families.

키워드

Binary analysisMalware classificationMalware detectionMalware similarityStatic analysisAutomated toolsBinary analysisClassification methodsInternet attacksMalware analysisMalware detectionMalwaresPerformance improvementsPrivate informationWide spreadsComputer crimeInternetSecurity of dataStatic analysis
제목
Malware classification method via binary content comparison
저자
Kang, BoojoongKim, TaekeunKwon, HeejunChoi, YangseoIm, Eul Gyu
DOI
10.1145/2401603.2401672
발행일
2012-10
유형
Conference Paper
저널명
Proceeding of the 2012 ACM Research in Applied Computation Symposium, RACS 2012
페이지
316 ~ 321