Malicious Code Detection Using Opcode Running Tree Representation
Ding Yuxin, Wei Dai, Zhang Yibin, Xue Chenglong · 2014 Ninth International Conference on P2P, Parallel, Grid, Cloud and Internet Computing · 2014
An opcode behavior based method is proposed to detect malware. Opcode behaviors are represented as opcode sequences from a decompiled executable. To accurately describe the malware behaviors, we construct the opcode running tree to simulate the dynamic execution of a program, and opcode n-grams are extracted to represent the features of an executable. The experimental results show that the opcode behaviors extracted by this method can fully represent the behavior characteristics of an executable. Compared with the detection method based the opcode distributions, the proposed method has higher overall accuracy and a lower false positive rate.