A Malware Detection Scheme Based on Mining Format Information

المؤلفون المشاركون

Bai, Jinrong
Wang, Junfeng
Zou, Guozhong

المصدر

The Scientific World Journal

العدد

المجلد 2014، العدد 2014 (31 ديسمبر/كانون الأول 2014)، ص ص. 1-11، 11ص.

الناشر

Hindawi Publishing Corporation

تاريخ النشر

2014-06-02

دولة النشر

مصر

عدد الصفحات

11

التخصصات الرئيسية

الطب البشري
تكنولوجيا المعلومات وعلم الحاسوب

الملخص EN

Malware has become one of the most serious threats to computer information system and the current malware detection technology still has very significant limitations.

In this paper, we proposed a malware detection approach by mining format information of PE (portable executable) files.

Based on in-depth analysis of the static format information of the PE files, we extracted 197 features from format information of PE files and applied feature selection methods to reduce the dimensionality of the features and achieve acceptable high performance.

When the selected features were trained using classification algorithms, the results of our experiments indicate that the accuracy of the top classification algorithm is 99.1% and the value of the AUC is 0.998.

We designed three experiments to evaluate the performance of our detection scheme and the ability of detecting unknown and new malware.

Although the experimental results of identifying new malware are not perfect, our method is still able to identify 97.6% of new malware with 1.3% false positive rates.

نمط استشهاد جمعية علماء النفس الأمريكية (APA)

Bai, Jinrong& Wang, Junfeng& Zou, Guozhong. 2014. A Malware Detection Scheme Based on Mining Format Information. The Scientific World Journal،Vol. 2014, no. 2014, pp.1-11.
https://search.emarefa.net/detail/BIM-1048948

نمط استشهاد الجمعية الأمريكية للغات الحديثة (MLA)

Bai, Jinrong…[et al.]. A Malware Detection Scheme Based on Mining Format Information. The Scientific World Journal No. 2014 (2014), pp.1-11.
https://search.emarefa.net/detail/BIM-1048948

نمط استشهاد الجمعية الطبية الأمريكية (AMA)

Bai, Jinrong& Wang, Junfeng& Zou, Guozhong. A Malware Detection Scheme Based on Mining Format Information. The Scientific World Journal. 2014. Vol. 2014, no. 2014, pp.1-11.
https://search.emarefa.net/detail/BIM-1048948

نوع البيانات

مقالات

لغة النص

الإنجليزية

الملاحظات

Includes bibliographical references

رقم السجل

BIM-1048948