On Malicious Software Classification

Jianhui Lin · 2008

In recent years, the number of malware families /variants has exploded dramatically. Automatic malware classification is becoming an important research area. In this paper, we propose a behavior-based automated classification method based on distance measure and machine learning. We represent a file by its runtime behavior in the form of sequenced events then structure the event information in a canonical format and store them in database. After machine learning classifier constructed the similarities and patterns learned by the classifiers are applied to classify new objects.

Read the paper · More papers on PaperTik