loading
Papers Papers/2022 Papers Papers/2022

Research.Publish.Connect.

Paper

Paper Unlock

Authors: Khanh-Huu-The Dam 1 and Tayssir Touili 2

Affiliations: 1 University Paris Diderot and LIPN, France ; 2 LIPN and CNRS and University Paris 13, France

Keyword(s): Machine Learning, Graph Kernel, Malware Detection, Static Analysis.

Abstract: Malware detection is nowadays a big challenge. The existing techniques for malware detection require a huge effort of engineering to manually extract the malicious behaviors. To avoid this tedious task of manually discovering malicious behaviors, we propose in this paper to apply learning for malware detection. Given a set of malwares and a set of benign programs, we show how learning techniques can be applied in order to detect malware. For that, we use abstract API graphs to represent programs. Abstract API graphs are graphs whose nodes are API functions and whose edges represent the order of execution of the different calls to the API functions (i.e., functions supported by the operating system). To learn malware, we apply well-known learning techniques based on Random Walk Graph Kernel (combined with Support Vector Machines). We can achieve a high detection rate with only few false alarms (98.93% for detection rate with 1.24% of false alarms). Moreover, we show that our techniqu es are able to detect several malwares that could not be detected by well-known and widely used antiviruses such as Avira, Kaspersky, Avast, Qihoo-360, McAfee, AVG, BitDefender, ESET-NOD32, F-Secure, Symantec or Panda. (More)

CC BY-NC-ND 4.0

Sign In Guest: Register as new SciTePress user now for free.

Sign In SciTePress user: please login.

PDF ImageMy Papers

You are not signed in, therefore limits apply to your IP address 3.138.200.66

In the current month:
Recent papers: 100 available of 100 total
2+ years older papers: 200 available of 200 total

Paper citation in several formats:
Dam, K. and Touili, T. (2017). Malware Detection based on Graph Classification. In Proceedings of the 3rd International Conference on Information Systems Security and Privacy - ICISSP; ISBN 978-989-758-209-7; ISSN 2184-4356, SciTePress, pages 455-463. DOI: 10.5220/0006209504550463

@conference{icissp17,
author={Khanh{-}Huu{-}The Dam. and Tayssir Touili.},
title={Malware Detection based on Graph Classification},
booktitle={Proceedings of the 3rd International Conference on Information Systems Security and Privacy - ICISSP},
year={2017},
pages={455-463},
publisher={SciTePress},
organization={INSTICC},
doi={10.5220/0006209504550463},
isbn={978-989-758-209-7},
issn={2184-4356},
}

TY - CONF

JO - Proceedings of the 3rd International Conference on Information Systems Security and Privacy - ICISSP
TI - Malware Detection based on Graph Classification
SN - 978-989-758-209-7
IS - 2184-4356
AU - Dam, K.
AU - Touili, T.
PY - 2017
SP - 455
EP - 463
DO - 10.5220/0006209504550463
PB - SciTePress