악성코드 분류를 위한 중요 연산부호 선택 및 그 유용성에 관한 연구

A Study on Selecting Key Opcodes for Malware Classification and Its Usefulness
  • 박정빈
  • 한경수
  • 김태근
  • 임을규

초록

Recently, the number of new malware and malware variants has dramatically increased. As a result, the time for analyzing malware and the efforts of malware analyzers have also increased. Therefore, malware classification helps malware analyzers decrease the overhead of malware analysis, and the classification is useful in studying the malware’s genealogy. In this paper, we proposed a set of key opcode to classify the malware. In our experiments, we selected the top 10-opcode as key opcode, and the key opcode decreased the training time of a Supervised learning algorithm by 91% with preserving classification accuracy.

키워드

malware analysismalware classificationopcodedecision treestatic analysisattribute selection악성코드 분석악성코드 분류연산부호의사결정나무정적분석속성 선택
제목
악성코드 분류를 위한 중요 연산부호 선택 및 그 유용성에 관한 연구
제목 (타언어)
A Study on Selecting Key Opcodes for Malware Classification and Its Usefulness
저자
박정빈한경수김태근임을규
발행일
2015-05
저널명
정보과학회논문지
42
5
페이지
558 ~ 565