53 14

Malware Analysis Using Visualized Image Matrices

Title
Malware Analysis Using Visualized Image Matrices
Author
임을규
Issue Date
2014-07
Publisher
HINDAWI PUBLISHING CORP, 315 MADISON AVE 3RD FLR, STE 3070, NEW YORK, NY 10017 USA
Citation
The Scientific World Journal Vol.2014
Abstract
This paper proposes a novel malware visual analysis method that contains not only a visualization method to convert binary files into images, but also a similarity calculation method between these images. The proposed method generates RGB-colored pixels on image matrices using the opcode sequences extracted from malware samples and calculates the similarities for the image matrices. Particularly, our proposed methods are available for packed malware samples by applying them to the execution traces extracted through dynamic analysis. When the images are generated, we can reduce the overheads by extracting the opcode sequences only from the blocks that include the instructions related to staple behaviors such as functions and application programming interface (API) calls. In addition, we propose a technique that generates a representative image for each malware family in order to reduce the number of comparisons for the classification of unknown samples and the colored pixel information in the image matrices is used to calculate the similarities between the images. Our experimental results show that the image matrices of malware can effectively be used to classify malware families both statically and dynamically with accuracy of 0.9896 and 0.9732, respectively.
URI
https://www.ncbi.nlm.nih.gov/pmc/articles/PMC4124712/http://hdl.handle.net/20.500.11754/55722
ISSN
1537-744X
DOI
10.1155/2014/132713
Appears in Collections:
COLLEGE OF ENGINEERING[S](공과대학) > COMPUTER SCIENCE(컴퓨터소프트웨어학부) > Articles
Files in This Item:
132713 (1).pdfDownload
Export
RIS (EndNote)
XLS (Excel)
XML


qrcode

Items in DSpace are protected by copyright, with all rights reserved, unless otherwise indicated.

BROWSE