ISSN 1000-1239 CN 11-1777/TP

• 信息安全 •

基于有效窗口和朴素贝叶斯的恶意代码分类

1. 1(中国石油信息技术服务中心 北京 100007) 2(北京航空航天大学计算机学院 北京 100191) 3(中国石油安全环保技术研究院HSE信息中心 北京 102206) (zhukenan@gmail.com)
• 出版日期: 2014-02-15

Malware Classification Approach Based on Valid Window and Naive Bayes

Zhu Kenan1, Yin Baolin2, Mao Yaming3, and Hu Yingnan3

1. 1(CNPC Information Technology Service Center, Beijing 100007) 2(School of Computer Science, Beihang University, Beijing 100191) 3(HSE Information Center, CNPC Research Institute of Safety and Environment Technology, Beijing 102206)
• Online: 2014-02-15

Abstract: Malware classification is the key problem in the field of malicious code analysis and intrusion detection. Existing malware classification approaches have low efficiency and poor accuracy because the raw behavior analysis data is large-scale with high noise data and interfered by random factors. To solve the above issues, taking the malware behavior reports as raw data, this paper analyzes the malware behavior characteristics, the operation similarity, the interference situation of random factors and noisy behavior data. Then it proposes a parameter valid window model for system call which improves the ability of operation sequence to describe behavior similarity. On this basis, the paper presents a malware classification approach based on naive Bayes machine learning model and parameter valid window. Moreover, an automatic malware behavior classifier prototype called MalwareFilter is designed and implemented in this paper. In case study, we evaluate the prototype using system call sequence reports generated through true malware. The experiment results show that our approach is effective, and the performance and accuracy of training and classification are improved through parameter valid window.