Opcode position aware metamorphic malware detection: Signature vs histogram approach | IEEE Conference Publication | IEEE Xplore

Opcode position aware metamorphic malware detection: Signature vs histogram approach


Abstract:

Unlike the conventional approaches in the detection of metamorphic malware, a novel statistical non signature based detection technique is proposed. The proposed methodol...Show More

Abstract:

Unlike the conventional approaches in the detection of metamorphic malware, a novel statistical non signature based detection technique is proposed. The proposed methodology aims to determine if alignment of locations or histogram of a specific opcode bigram is superior in the classification of metamorphic malware samples. In this work, we used Term Frequency-Inverse Document Frequency-Class Frequency (TF-IDF-CF) as feature selection method for synthesizing prominent features. Vector space models has been constructed by preserving hamming distance and Smith Waterman local sequence alignment score. Experiment results depicted that with Smith Waterman sequence alignment, best results were obtained with 300 significant malware features (94.01% accuracy, 92.24% F-measure, 100% precision and 49.89% recall). However, hamming distance based reference model, with 7 bigrams resulted in 100% precision, 99.76% accuracy, 99.71% F-measure and 99.42% recall.
Date of Conference: 11-13 March 2015
Date Added to IEEE Xplore: 04 May 2015
ISBN Information:
Conference Location: New Delhi, India

Contact IEEE to Subscribe

References

References is not available for this document.