Extracting representative API patterns of malware families using multiple sequence alignments
- Authors
- Cho, In Kyeom; Im, Eul Gyu
- Issue Date
- Oct-2015
- Publisher
- Association for Computing Machinery, Inc
- Keywords
- Malware classification; Multiple sequence alignment; Representative API pattern
- Citation
- Proceeding of the 2015 Research in Adaptive and Convergent Systems, RACS 2015, pp.308 - 313
- Indexed
- SCOPUS
- Journal Title
- Proceeding of the 2015 Research in Adaptive and Convergent Systems, RACS 2015
- Start Page
- 308
- End Page
- 313
- URI
- https://scholarworks.bwise.kr/hanyang/handle/2021.sw.hanyang/156198
- DOI
- 10.1145/2811411.2811543
- ISSN
- 0000-0000
- Abstract
- Nowadays malware developers use various techniques to avoid detection of antivirus software. For variants of malware, existing signature based detection method could be avoidable because those have some differences in static information like code or strings. Therefore, to detect and classify malware variants, a behavior based detection is required. This paper proposes a technique to extract a representative API pattern from API call sequences of a malware family using multiple sequence alignment (MSA) algorithm to measure similarities among malware variants. To extract API call sequences of malware, a sandbox tool was used. After that, the Clustal algorithm, a popular MSA algorithm used in the Bioinformatics field, was applied to malware API call sequences, and the representative API pattern was extracted from the results of MSA. Experiments to test the extracted API patterns that are used to classify malware variants were carried out, and we measured classification accuracy of the representative API pattern of each family. The experimental results show that our proposed method can be effective to classify malware families.
- Files in This Item
-
Go to Link
- Appears in
Collections - 서울 공과대학 > 서울 컴퓨터소프트웨어학부 > 1. Journal Articles

Items in ScholarWorks are protected by copyright, with all rights reserved, unless otherwise indicated.