A study on similarity calculation method for API invocation sequences

Citations

SCOPUS

0

초록

Malware variants have been developed and spread in the Internet, and the number of new malware variants is increases every year. Recently, malware is applied with obfuscation and mutation techniques to hide its existence, and malware variants are developed with various automatic tools that transform the properties of existing malware to avoid static analysis based malware detection systems. It is difficult to detect such obfuscated malware with static-based signatures, so we have designed a detection system based on dynamic analysis. In this paper, we propose a dynamic analysis based system that uses the API invocation sequences to compare behaviors of suspicious software with behaviors of existing malware.

키워드

API invocation sequenceDynamic analysisMalware detectionSimilarity calculation methodCalculationsComputer crimeDynamic analysisMalwareRough set theoryAPI invocation sequenceAutomatic toolsDetection systemMalware detectionSimilarity calculationStatic analysis
제목
A study on similarity calculation method for API invocation sequences
저자
Shim, Yu JinKim, Tae GuenIm, Eul Gyu
DOI
10.1007/978-3-319-25754-9_43
발행일
2015-11
유형
Conference Paper
저널명
Lecture Notes in Computer Science
9436
페이지
492 ~ 501