Malware classification for identifying author groups: A graph-based approach

  • Hong, Jiwon
  • Park, Sung-Jun
  • Kim, Taeri
  • Noh, Yung-Kyun
  • Kim, Sang-Wook
  • 외 2명
Citations

SCOPUS

7

초록

As our lives become increasingly dependent on computer software, the threat of malware attacks is getting greater. By slightly modifying the previous version to avoid malware detection, the attackers can continuously release new malwares with ease. However, malwares released by a group of authors might contain some evidence among them that they are developed by the same group of authors. Such information can be used for digital forensics, law enforcement, and deeper analysis of malwares. In this paper, we propose a graph-based approach to classify author groups of given malware samples. In addition, we propose graph refinement strategies to improve classification accuracies. Via extensive experiments on a real-world dataset, we verify our graph-based classification could benefit author group classification of malwares than traditional feature-based SVM. We also verify the proposed graph refinement strategies increase the accuracy of the classification. © 2019 Copyright held by the owner/author(s). Publication rights licensed to ACM.

키워드

Author group identificationGraph-based classificationMalware classificationClassification (of information)Digital forensicsGraphic methodsSupport vector machinesClassification accuracyGraph-based classificationsGroup classificationGroup identificationMalware attacksMalware classificationsMalware detectionRefinement strategyMalware
제목
Malware classification for identifying author groups: A graph-based approach
저자
Hong, JiwonPark, Sung-JunKim, TaeriNoh, Yung-KyunKim, Sang-WookKim, DongphilKim, Wonho
DOI
10.1145/3338840.3355684
발행일
2019-09
유형
Conference Paper
저널명
Proceedings of the 2019 Research in Adaptive and Convergent Systems, RACS 2019
페이지
169 ~ 174