,Automatic malware classification and new malware detection using machine learning

来源 :信息与电子工程前沿(英文版) | 被引量 : 0次 | 上传用户:yhmlivefor51
下载到本地 , 更方便阅读
声明 : 本文档内容版权归属内容提供方 , 如果您对本文有版权争议 , 可与客服联系进行内容授权或下架
论文部分内容阅读
The explosive growth of malware variants poses a major threat to information security. Traditional anti-virus systems based on signatures fail to classify unknown malware into their corresponding families and to detect new kinds of malware pro-grams. Therefore, we propose a machine leaing based malware analysis system, which is composed of three modules: data processing, decision making, and new malware detection. The data processing module deals with gray-scale images, Opcode n-gram, and import functions, which are employed to extract the features of the malware. The decision-making module uses the features to classify the malware and to identify suspicious malware. Finally, the detection module uses the shared nearest neighbor (SNN) clustering algorithm to discover new malware families. Our approach is evaluated on more than 20000 malware instances, which were collected by Kingsoft, ESET NOD32, and Anubis. The results show that our system can effectively classify the un-known malware with a best accuracy of 98.9%, and successfully detects 86.7% of the new malware.
其他文献
通过1995年和1996年两年的田间试验及室内分析,对不同结荚习性大豆的开花、结荚、鼓粒特性进行了比较研究,其内容主要包括不同结荚习性大豆开花时间、开花动态、开花顺序、开
21世纪的第一个五年,是我国改革开放深入发展,经济结构体制实行战略性调整,建立比较完善的社会主义市场经济体制,实施现代化建设第三步战略部署的关键时期。世界多极化趋势不可逆转
In mode energy-saving replication storage systems, a primary group of disks is always powered up to serve incoming requests while other disks are often spun dow
该试验采用单体分析法,对这两类品系的几个重要农艺性状进行了基因定位研究.玉 皮分枝麦和骊英3号分枝麦是稳定的穗分枝型普通小麦品系.对它们进行遗传分析得到如下结论:1.长
本实验选用糯性青稞品种甘垦5号和非糯性青稞品种北青6号和昆仑12号作为试验材料,以双波长分光光度法测定3个青稞品种籽粒灌浆期中直链淀粉与支链淀粉含量的动态变化;通过测定酶活分析研究了淀粉代谢的关键酶活性变化;通过RT-PCR研究并分析了淀粉代谢关键酶编码基因的表达量,以及不同基因表达量之间和基因表达量与对应酶活的相互关系。结果表明:1.随着籽粒灌浆期的进行甘垦5号、北青6号和昆仑12号的支链淀粉的
长期以来,一提起新闻真实性问题,人们总是把眼光盯在报纸版面的字眼上,什么人名、地点有误,或时间相差有几等等。当然,这也是应该的。但是,这远远不够,还应该查一查那些应报
学位
从人的能力形成途径来看,人才能力主要可分三种;他育能,自育能;以自育为主助以他育之能。能力形成的途径不同,能力性质亦不同,基利弊显而易见。 他育能,可谓外力附着能。由于“他育
A distributed fault-tolerant strategy for the controller area network based electric swing system of hybrid excavators is proposed to achieve good performance u
该试验以1347纯系品种做为试验材料,采用3因素二次回归通用旋转组俣设计,系统地研究了肥密因素对产量及一些形态生理指标的影响.通过计算机模拟,得出产量与密度(x)、施氮量(x