G3MD: Mining frequent opcode sub-graphs for metamorphic malware detection of existing families. (1st December 2018)
- Record Type:
- Journal Article
- Title:
- G3MD: Mining frequent opcode sub-graphs for metamorphic malware detection of existing families. (1st December 2018)
- Main Title:
- G3MD: Mining frequent opcode sub-graphs for metamorphic malware detection of existing families
- Authors:
- Khalilian, Alireza
Nourazar, Amir
Vahidi-Asl, Mojtaba
Haghighi, Hassan - Abstract:
- Highlights: We hypothesize that metamorphic malwares of a certain family share some sub-structures. We propose an approach based on mining frequent sub-graphs. We achieved dramatically high precision (over 99% in most cases). Abstract: Attackers leverage various obfuscation techniques to create a metamorphic malware that can evade from detection by anti-malwares. To defeat, we propose Graph Mining for Metamorphic Malware Detection (G3MD), an intelligent system for static detection of metamorphic malwares. G3MD demonstrates one of the many aspects of what the current generation of machine-learning techniques and expert systems can do. It extends what is known about practical application of machine-learning techniques in the field of information security. It is intended to alleviate the burden of human experts and underlying costs. The novelty of G3MD is to apply graph mining on the opcode graphs of a metamorphic family of malwares to extract the frequent sub-graphs, so called micro-signatures . Based on these sub-graphs, a classifier is trained to distinguish between a benign file and a metamorphic malware. We conducted experiments on four families of metamorphic malwares common in previous studies, namely Next Generation Virus Generation Kit (NGVCK), Second Generation Virus Generator (G2), and Mass Produced Code Generation Kit (MPCGEN) viruses and Metamorphic Worm (MWOR) worms. The precision (over 99% in most cases) of metamorphic malware detection by the proposed approachHighlights: We hypothesize that metamorphic malwares of a certain family share some sub-structures. We propose an approach based on mining frequent sub-graphs. We achieved dramatically high precision (over 99% in most cases). Abstract: Attackers leverage various obfuscation techniques to create a metamorphic malware that can evade from detection by anti-malwares. To defeat, we propose Graph Mining for Metamorphic Malware Detection (G3MD), an intelligent system for static detection of metamorphic malwares. G3MD demonstrates one of the many aspects of what the current generation of machine-learning techniques and expert systems can do. It extends what is known about practical application of machine-learning techniques in the field of information security. It is intended to alleviate the burden of human experts and underlying costs. The novelty of G3MD is to apply graph mining on the opcode graphs of a metamorphic family of malwares to extract the frequent sub-graphs, so called micro-signatures . Based on these sub-graphs, a classifier is trained to distinguish between a benign file and a metamorphic malware. We conducted experiments on four families of metamorphic malwares common in previous studies, namely Next Generation Virus Generation Kit (NGVCK), Second Generation Virus Generator (G2), and Mass Produced Code Generation Kit (MPCGEN) viruses and Metamorphic Worm (MWOR) worms. The precision (over 99% in most cases) of metamorphic malware detection by the proposed approach corroborates its effectiveness over other existing approaches. … (more)
- Is Part Of:
- Expert systems with applications. Volume 112(2018)
- Journal:
- Expert systems with applications
- Issue:
- Volume 112(2018)
- Issue Display:
- Volume 112, Issue 2018 (2018)
- Year:
- 2018
- Volume:
- 112
- Issue:
- 2018
- Issue Sort Value:
- 2018-0112-2018-0000
- Page Start:
- 15
- Page End:
- 33
- Publication Date:
- 2018-12-01
- Subjects:
- Metamorphic malware -- Graph mining -- Opcode graph -- Malware classification and detection -- Obfuscation
Expert systems (Computer science) -- Periodicals
Systèmes experts (Informatique) -- Périodiques
Electronic journals
006.33 - Journal URLs:
- http://www.sciencedirect.com/science/journal/09574174 ↗
http://www.elsevier.com/journals ↗ - DOI:
- 10.1016/j.eswa.2018.06.012 ↗
- Languages:
- English
- ISSNs:
- 0957-4174
- Deposit Type:
- Legaldeposit
- View Content:
- Available online (eLD content is only available in our Reading Rooms) ↗
- Physical Locations:
- British Library DSC - 3842.004220
British Library DSC - BLDSS-3PM
British Library HMNTS - ELD Digital store - Ingest File:
- 7159.xml