A fine-grained classification approach for the packed malicious code

  • Authors:
  • Shanqing Guo;Shuangshuang Li;Yan Yu;Anlei Hu;Tao Ban

  • Affiliations:
  • School of Computer Science and Technology, Shandong University, China;School of Computer Science and Technology, Shandong University, China;School of Computer Science, Nanjing University of Science & Technology, China;DNSLAB, China Internet Network Information Center, Beijing, China;National Institute of Information and Communications Technology, Japan

  • Venue:
  • ICICS'12 Proceedings of the 14th international conference on Information and Communications Security
  • Year:
  • 2012

Quantified Score

Hi-index 0.00

Visualization

Abstract

Executable packing is the most common technique to evade detection by anti-virus software.Many signature-based unpackers have been presented to uncover hidden viruses,which make the signature-based anti-virus software successfully detect the packed malicious code. However,these universal unpackers are computationally expensive and scanning large collections of executables may take several hours or even days.In order to improve the computational efficiency, Machine learning techniques have recently been proven effective in solving the focused issues,but up to now,no methods can show what packing method has been used in it.In this paper we proposed a fine-grained detection method to detect whether a malicious code has been packed and which method is been used to.This method firstly extract a hex-string from the target object file and then apply a String-Kernel-Based SVM Classifier to implement the fast detection of packed malicious code.We also show that our system achieves very high detection accuracy of packed executables, so that only executables detected as packed will be sent to an universal unpacker, thus saving a significant amount of processing time.