Fast malware family detection method using control flow graphs

  • Kang, Boojoong
  • Kim, Hye Seon
  • Kim, T.
  • Kwon, H.
  • Im, E.G.
Citations

SCOPUS

14

초록

As attackers make variants of existing malware, it is possible to detect unknown malware by comparing with already-known malware's information. Control flow graphs have been used in dynamic analysis of program source code. In this paper, we proposed a new method which can analyze and detect malware binaries using control flow graphs and Bloom filter by abstracting common characteristics of malware families. The experimental results showed that processing overhead of our proposed method is much lower than n-gram based methods.

키워드

Bloom filtercontrol flow graphmalware analysisnetwork securityBloom filterscontrol flow graphControl flow graphsDetection methodsMalware analysisMalwaresProcessing overheadProgram source codesBlooms (metal)Data flow analysisFlow graphsGraphic methodsNetwork securityComputer crime
제목
Fast malware family detection method using control flow graphs
저자
Kang, BoojoongKim, Hye SeonKim, T.Kwon, H.Im, E.G.
DOI
10.1145/2103380.2103439
발행일
2011-11
유형
Conference Paper
저널명
Proceedings of the 2011 ACM Research in Applied Computation Symposium, RACS 2011
페이지
287 ~ 292