Analysis and evaluation of dynamic feature-based malware detection methods


KAKIŞIM A., Nar M., Carkaci N., Sogukpinar I.

11th International Conference on Security for Information Technology and Communications, SecITC 2018, Bucharest, Romanya, 8 - 09 Kasım 2018, cilt.11359 LNCS, ss.247-258, (Tam Metin Bildiri) identifier

  • Yayın Türü: Bildiri / Tam Metin Bildiri
  • Cilt numarası: 11359 LNCS
  • Doi Numarası: 10.1007/978-3-030-12942-2_19
  • Basıldığı Şehir: Bucharest
  • Basıldığı Ülke: Romanya
  • Sayfa Sayıları: ss.247-258
  • Anahtar Kelimeler: API-call, Behavior-based analysis, Dynamic analysis, Malware detection, Polymorphic/metamorphic malware, Usage system library
  • Yıldız Teknik Üniversitesi Adresli: Evet

Özet

While increasing the threat of malware for information systems, researchers strive to find alternative malware detection methods based on static, dynamic and hybrid analysis. Due to obfuscation techniques to bypass the static analysis, dynamic methods become more useful to detect malware. Therefore, most of the researches focus on dynamic behavior analysis of malicious software. In this work, our main objective is to find more discriminative dynamic features to detect malware executables by analyzing different dynamic features with common malware detection approaches. Moreover, we analyze separately different features obtained in dynamic analysis, such as API-call, usage system library and operations, to observe the contributions of these features to malware detection and classification success. For this purpose, we evaluate the performance of some dynamic feature-based malware detection and classification approaches using four data sets that contain real and synthetic malware executables.