Title
Scalable malware clustering through coarse-grained behavior modeling
Abstract
Anti-malware vendors receive several thousand new malware (malicious software) variants per day. Due to large volume of malware samples, it has become extremely important to group them based on their malicious characteristics. Grouping of malware variants that exhibit similar behavior helps to generate malware signatures more efficiently. Unfortunately, exponential growth of new malware variants and huge-dimensional feature space, as used in existing approaches, make the clustering task very challenging and difficult to scale. Furthermore, malware behavior modeling techniques proposed in the literature do not scale well, where malware feature space grows in proportion with the number of samples under examination. In this paper, we propose a scalable malware behavior modeling technique that models the interactions between malware and sensitive system resources in a coarse-grained manner. Coarse-grained behavior modeling enables us to generate malware feature space that does not grow in proportion with the number of samples under examination. A preliminary study shows that our approach generates 289 times less malware features and yet improves the average clustering accuracy by 6.20% comparing to a state-of-the-art malware clustering technique.
Year
DOI
Venue
2012
10.1145/2393596.2393627
SIGSOFT FSE
Keywords
Field
DocType
new malware variant,malware variant,malware behavior modeling technique,coarse-grained behavior modeling,malware feature,thousand new malware,malware signature,state-of-the-art malware,scalable malware behavior modeling,malware sample,malware feature space
Data mining,Feature vector,Computer science,Computer security,Theoretical computer science,Malware,Cluster analysis,Scalability
Conference
Citations 
PageRank 
References 
5
0.45
3
Authors
3
Name
Order
Citations
PageRank
Mahinthan Chandramohan122211.67
Hee Beng Kuan Tan248945.05
Lwin Khin Shar318014.56