Classification of polymorphic and metamorphic malware samples based on their behavior

Ksenia Tsyganok, Evgeny Tumoyan, Liudmila K. Babenko, Maxim Vladimirovich Anikeev · 2012

This work proposes a new method of malware classification based on behavior features. We developed a proximity measure for programs, which takes into account WinAPI calls, their arguments, and files handled by these programs. Cluster analysis is used for grouping. The method was tested with actual malware samples.

Read the paper · More papers on PaperTik