Simple substitution distance and metamorphic detection

  • Authors:
  • Gayathri Shanmugam;Richard M. Low;Mark Stamp

  • Affiliations:
  • Department of Computer Science, San Jose State University, San Jose, USA;Department of Mathematics, San Jose State University, San Jose, USA;Department of Computer Science, San Jose State University, San Jose, USA

  • Venue:
  • Journal in Computer Virology
  • Year:
  • 2013

Quantified Score

Hi-index 0.00

Visualization

Abstract

To evade signature-based detection, metamorphic viruses transform their code before each new infection. Software similarity measures are a potentially useful means of detecting such malware. We can compare a given file to a known sample of metamorphic malware and compute their similarity--if they are sufficiently similar, we classify the file as malware of the same family. In this paper, we analyze an opcode-based software similarity measure inspired by simple substitution cipher cryptanalysis. We show that the technique provides a useful means of classifying metamorphic malware.