Malware classification using byte sequence information

Citations

SCOPUS

28

초록

The number of new malware and new malware variants have been increasing continuously. Security experts analyze malware to capture the malicious properties of malware and to generate signatures or detection rules, but the analysis overheads keep increasing with the increasing number of malware. To analyze a large amount of malware, various kinds of automatic analysis methods are in need. Recently, deep learning techniques such as convolutional neural network (CNN) and recurrent neural network (RNN) have been applied for malware classifications. The features used in the previous approches are mostly based on API (Application Programming Interface) information, and the API invocation information can be obtained through dynamic analysis. However, the invocation information may not reflect malicious behaviors of malware because malware developers use various analysis avoidance techniques. Therefore, deep learning-based malware analysis using other features still need to be developed to improve malware analysis performance. In this paper, we propose a malware classification method using the deep learning algorithm based on byte information. Our proposed method uses images generated from malware byte information that can reflect malware behavioral context, and the convolutional neural network-based sentence analysis is used to process the generated images. We performed several experiments to show the effecitveness of our proposed method, and the experimental results show that our method showed higher accuracy than the naive CNN model, and the detection accuracy was about 99%.

키워드

CNNDeep learningMalware classificationStatic analysisApplication programming interfaces (API)Classification (of information)Computer crimeConvolutionDeep learningLearning algorithmsNetwork securityRecurrent neural networksStatic analysisAnalysis avoidancesAutomatic analysis methodConvolutional neural networkConvolutional Neural Networks (CNN)Detection accuracyLearning techniquesMalware classificationsRecurrent neural network (RNN)Malware
제목
Malware classification using byte sequence information
저자
Jung, ByunghoKim, TaeguenIm, Eul Gyu
DOI
10.1145/3264746.3264775
발행일
2018-10
유형
Conference Paper
저널명
Proceedings of the 2018 Research in Adaptive and Convergent Systems, RACS 2018
페이지
143 ~ 148