Malware obfuscation detection via maximal patterns

  • Authors:
  • Jian Li;Ming Xu;Ning Zheng;Jian Xu

  • Affiliations:
  • Institute of Computer Application Technology, Hangzhou Dianzi University, P. R. China;Institute of Computer Application Technology, Hangzhou Dianzi University, P. R. China;Institute of Computer Application Technology, Hangzhou Dianzi University, P. R. China;Institute of Computer Application Technology, Hangzhou Dianzi University, P. R. China

  • Venue:
  • IITA'09 Proceedings of the 3rd international conference on Intelligent information technology application
  • Year:
  • 2009

Quantified Score

Hi-index 0.00

Visualization

Abstract

Malware obfuscation is defined as a program transformation. It is always used in malware to evade detection from anti-malware software. In this paper, we propose a method to detect malware obfuscation using maximal patterns. Maximal pattern is a subsequence in malware's runtime system call sequence, which frequently appears in program execution, and can be used to describe the program specific behavior. The maximal pattern sequence is extracted from the malware's runtime system calls, and the similarity between two pattern sequences will be measured by evolutionary similarity. Based on the real-world malwares test data, the experiment results have shown that our method can efficiently detect malware obfuscation.