Extracting representative API patterns of malware families using multiple sequence alignments

Citations

SCOPUS

15

초록

Nowadays malware developers use various techniques to avoid detection of antivirus software. For variants of malware, existing signature based detection method could be avoidable because those have some differences in static information like code or strings. Therefore, to detect and classify malware variants, a behavior based detection is required. This paper proposes a technique to extract a representative API pattern from API call sequences of a malware family using multiple sequence alignment (MSA) algorithm to measure similarities among malware variants. To extract API call sequences of malware, a sandbox tool was used. After that, the Clustal algorithm, a popular MSA algorithm used in the Bioinformatics field, was applied to malware API call sequences, and the representative API pattern was extracted from the results of MSA. Experiments to test the extracted API patterns that are used to classify malware variants were carried out, and we measured classification accuracy of the representative API pattern of each family. The experimental results show that our proposed method can be effective to classify malware families.

키워드

Malware classificationMultiple sequence alignmentRepresentative API patternBioinformaticsComputer crimeAntivirus softwaresAPI patternsBehavior-based detectionClassification accuracyMalware classificationsMultiple sequence alignment algorithmMultiple sequence alignmentsSignature based detectionsMalware
제목
Extracting representative API patterns of malware families using multiple sequence alignments
저자
Cho, In KyeomIm, Eul Gyu
DOI
10.1145/2811411.2811543
발행일
2015-10
유형
Conference Paper
저널명
Proceeding of the 2015 Research in Adaptive and Convergent Systems, RACS 2015
페이지
308 ~ 313