Malicious Software Detection and Classification utilizing Temporal-Graphs of System-call Group Relations

12/27/2018
by   Anna Mpanti, et al.
0

In this work we propose a graph-based model that, utilizing relations between groups of System-calls, distinguishes malicious from benign software samples and classifies the detected malicious samples to one of a set of known malware families. More precisely, given a System-call Dependency Graph (ScDG) that depicts the malware's behavior, we first transform it to a more abstract representation, utilizing the indexing of System-calls to a set of groups of similar functionality, constructing thus an abstract and mutation-tolerant graph that we call Group Relation Graph (GrG); then, we construct another graph representation, which we call Coverage Graph (CvG), that depicts the dominating relations between the nodes of a GrG graph. Based on the research so far in the field, we pointed out that behavior-based graph representations had not leveraged the aspect of the temporal evolution of the graph. Hence, the novelty of our work is that, preserving the initial representations of GrG and CvG graphs, we focus on augmenting the potentials of theses graphs by adding further features that enhance its abilities on detecting and further classifying to a known malware family an unknown malware sample. To that end, we construct periodical instances of the graph that represent its temporal evolution concerning its structural modifications, creating another graph representation that we call Temporal Graphs. In this paper, we present the theoretical background behind our approach, discuss the current technological status on malware detection and classification and demonstrate the overall architecture of our proposed detection and classification model alongside with its underlying main principles and its structural key-components.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
06/10/2019

SCGDet: Malware Detection using Semantic Features Based on Reachability Relation

Recently, with the booming development of software industry, more and mo...
research
02/11/2019

Analyzing, Comparing, and Detecting Emerging Malware: A Graph-based Approach

The growth in the number of Android and Internet of Things (IoT) devices...
research
11/18/2022

Clustering based opcode graph generation for malware variant detection

Malwares are the key means leveraged by threat actors in the cyber space...
research
11/23/2020

On a Bayesian Approach to Malware Detection and Classification through n-gram Profiles

Detecting and correctly classifying malicious executables has become one...
research
11/13/2015

Novel Feature Extraction, Selection and Fusion for Effective Malware Family Classification

Modern malware is designed with mutation characteristics, namely polymor...
research
10/18/2022

A Novel Feature Representation for Malware Classification

In this study we have presented a novel feature representation for malic...
research
12/01/2020

Classifying Malware Using Function Representations in a Static Call Graph

We propose a deep learning approach for identifying malware families usi...

Please sign up or login with your details

Forgot password? Click here to reset