Metamorphic Malware Detection Using Linear Discriminant Analysis and Graph Similarity

11/10/2018
by   Reza Mirzazadeh, et al.
0

The most common malware detection approaches which are based on signature matching and are not sufficient for metamorphic malware detection, since virus kits and metamorphic engines can produce variants with no resemblance to one another. Metamorphism provides an efficient way for eluding malware detection software kits. Code obfuscation methods like dead-code insertion are also widely used in metamorphic malware. In order to address the problem of detecting mutated generations, we propose a method based on Opcode Graph Similarity (OGS). OGS tries to detect metamorphic malware using the similarity of opcode graphs. In this method, all nodes and edges have a respective effect on classification, but in the proposed method, edges of graphs are pruned using Linear Discriminant Analysis (LDA). LDA is based on the concept of searching for a linear combination of predictors that best separates two or more classes. Most distinctive edges are identified with LDA and the rest of edges are removed. The metamorphic malware families considered here are NGVCK and metamorphic worms that we denote these worms as MWOR. The results show that our approach is capable of classifying metamorphosed instances with no or minimum false alarms. Also, our proposed method can detect NGVCK and MWOR with high accuracy rate.

READ FULL TEXT

page 1

page 5

research
06/22/2019

Andro-Simnet: Android Malware Family Classification Using Social Network Analysis

While the rapid adaptation of mobile devices changes our daily life more...
research
10/17/2019

Heterogeneous Graph Matching Networks

Information systems have widely been the target of malware attacks. Trad...
research
05/06/2023

Bypassing antivirus detection: old-school malware, new tricks

Being on a mushrooming spree since at least 2013, malware can take a lar...
research
11/08/2021

OMD: Orthogonal Malware Detection Using Audio, Image, and Static Features

With the growing number of malware and cyber attacks, there is a need fo...
research
04/19/2017

Semi-supervised classification for dynamic Android malware detection

A growing number of threats to Android phones creates challenges for mal...
research
06/23/2021

MG-DVD: A Real-time Framework for Malware Variant Detection Based on Dynamic Heterogeneous Graph Learning

Detecting the newly emerging malware variants in real time is crucial fo...
research
12/01/2020

Classifying Malware Using Function Representations in a Static Call Graph

We propose a deep learning approach for identifying malware families usi...

Please sign up or login with your details

Forgot password? Click here to reset