Toward extracting malware features for classification using static and dynamic analysis

Young Han Choi, Byoung Jin Han, Byung Chul Bae, Hyung Geun Oh, Ki Wook Sohn

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

24 Scopus citations

Abstract

Because of a great many malware, they must be classified into malware family before being analyzed manually. Otherwise, we cannot analyze and handle them in real time. By classifying them, we can analyze only some unknown malwares intensively. In this paper, we propose a framework for malware classification using static and dynamic analysis. We focus on techniques that extract malware features. We name the framework GATTACA(Genome-based ATTACk geneAlogy) from the movie that covers genome of human. We define features of Malware as Mal-DNA(Malware DNA). Mal-DNA includes static, hybrid and dynamic characteristics. In short, GATTACA is the framework for extracting Mal-DNA from malwares and classifying them. GATTACA consists of three components: (1) START(STatic Analyzer using vaRious Techniques) extracts static Mal-DNA of malware. (2) DeBON(Debugging-based Behavior mOnitor and aNalyzer) extracts hybrid and dynamic Mal-DNA of them. (3) CLAM(CLassifier using Mal-DNA) classifies malwares based on Mal-DNA using machine learning. START and DeBON extract Mal-DNA, and CLAM classifies malwares based on Mal-DNA. In this paper, we target on START and DeBON extracting Mal-DAN from malwares.

Original languageEnglish
Title of host publicationProceedings - 2012 8th International Conference on Computing and Networking Technology (INC, ICCIS and ICMIC), ICCNT 2012
Pages126-129
Number of pages4
StatePublished - 2012
Event2012 8th International Conference on Computing and Networking Technology (INC, ICCIS and ICMIC), ICCNT 2012 - Gyeongju, Korea, Republic of
Duration: 27 Aug 201229 Aug 2012

Publication series

NameProceedings - 2012 8th International Conference on Computing and Networking Technology (INC, ICCIS and ICMIC), ICCNT 2012

Conference

Conference2012 8th International Conference on Computing and Networking Technology (INC, ICCIS and ICMIC), ICCNT 2012
Country/TerritoryKorea, Republic of
CityGyeongju
Period27/08/1229/08/12

Keywords

  • Feature Extraction
  • Malware Classification

Fingerprint

Dive into the research topics of 'Toward extracting malware features for classification using static and dynamic analysis'. Together they form a unique fingerprint.

Cite this