跳到主要导航 跳到搜索 跳到主要内容

A layered detection method for Malware identification

  • Xi'an Jiaotong University

科研成果: 书/报告/会议事项章节会议稿件同行评审

摘要

In recent years, millions of new malicious programs are produced by Pa mature industry of malware production. These programs have tremendous challenges on the signature-based anti-virus products and pose great threats on network and information security. Machine learning techniques are applicable for detecting unknown malicious programs without knowing their signatures. In this paper, a Layered Detection (LD) method is developed to detect malwares with a two-layer framework. The Low-Level-Classifiers (LLC) are employed to identify whether the programs perform any malicious functions according to the API-calls of the programs. The Up-level-Classifier (ULC) is applied to detect malwares according to the low level function identification. The LD method is compared with many classical classification algorithms with comprehensive test datasets containing 16135 malwares and 1800 benign programs. The experiments demonstrate that the LD method outperforms other algorithms in terms of detection accuracy.

源语言英语
主期刊名Network and Parallel Computing - 8th IFIP International Conference, NPC 2011, Proceedings
166-175
页数10
DOI
出版状态已出版 - 2011
活动8th IFIP International Conference on Network and Parallel Computing, NPC 2011 - Changsha, 中国
期限: 21 10月 201123 10月 2011

出版系列

姓名Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
6985 LNCS
ISSN(印刷版)0302-9743
ISSN(电子版)1611-3349

会议

会议8th IFIP International Conference on Network and Parallel Computing, NPC 2011
国家/地区中国
Changsha
时期21/10/1123/10/11

学术指纹

探究 'A layered detection method for Malware identification' 的科研主题。它们共同构成独一无二的指纹。

引用此