Research on the Classification Model of Similarity Malware using Fuzzy Hash

C. S. Park, Hyunji Chung, Kwang-Seok Seo, Sangjin Lee · Information Security and Cryptology · 2012

ABSTRACT In the past about 10 different kinds of malicious code were found in one day on the average. However, the number of malicious codes that are found has rapidly increased reachingov er 55,000 during the last 10 year. A large number of malicious codes, however, are not new kinds of malicious codes but most o f them are new variants of the existing malicious codes as same functions are newly added into the existing malicious code s, or the existing malicious codes are modified to evade anti-virus detection. To deal with a lot of malicious codes inc luding new malicious codes and variants of the existing malicious codes, we need to compare the malicious codes in the past and t he similarity and classify the new malicious codes and the variants of the existing malicious codes. A former calculation method of the similarity on the existing malicious codes compar e external factors of IPs, URLs, API, Strings, etc or source code levels. The former calculation method of the similarity takes time due to the number of malicious codes and comparable factor s on the increase, and it leads to employing fuzzy hashing to reduce the amount of calculation. The existing fuzzy hashing , however, has some limitations, and it causes come problems to the former calculation of the similarity. Therefore, this re search paper has suggested a new comparison method for malicious codes to improve performance of the calculation of the similarity using fuzzy hashing and also a classification method employing the new comparison method.Keywords: Fuzzy Hash, Malware, Similarity접수일(2012년 4월 16일), 수정일(2012년 9월 19일), 게재확정일(2012년 11월 7일)* 본 논문은 지식경제부 산업융 합원천기술개발사업으로 지원된 연구결과입니다. [10035157, 실시간 분석을 위한 디지털 포렌식 기술 개발]† 주저자, [email protected]‡ 교신저자, [email protected]

Read the paper · More papers on PaperTik