A static heuristic approach to detecting malware targets

Nowadays malware writers usually employ several obfuscation techniques to evade detection. The number of variants detected each day has been increasing significantly. Unfortunately traditional detection approaches such as signature scanning are becoming inefficient to detect such malwares. Researche...

Ausführliche Beschreibung

Gespeichert in:
Bibliographische Detailangaben
Veröffentlicht in:Security and communication networks 2015-11, Vol.8 (17), p.3015-3027
Hauptverfasser: Zakeri, Mohaddeseh, Faraji Daneshgar, Fatemeh, Abbaspour, Maghsoud
Format: Artikel
Sprache:eng
Schlagworte:
Online-Zugang:Volltext
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
Beschreibung
Zusammenfassung:Nowadays malware writers usually employ several obfuscation techniques to evade detection. The number of variants detected each day has been increasing significantly. Unfortunately traditional detection approaches such as signature scanning are becoming inefficient to detect such malwares. Researches show that these obfuscations make some anomalies in Portable Executable files. In this paper, by focusing on important static heuristic features and fuzzy classification algorithms, we tried to detect malwares and packed files. In addition, we used preprocessing to evade anomaly exceptions in benign files that improved our detection results. The experimental results, using over 63 000 file samples, indicate that the proposed detector achieves high detection results with low false positive and false negative rates. Furthermore, our experimental results on new malware samples that had been undetectable for many years by antivirus products and new custom packers, show that our system works well with new and unknown samples too. Copyright © 2015 John Wiley & Sons, Ltd. In this paper, by focusing on important static heuristic features and fuzzy classification algorithms, we tried to detect malwares and packed files. In addition, we used preprocessing to evade anomalies exception in benign files that improved our detection.
ISSN:1939-0114
1939-0122
DOI:10.1002/sec.1228