Fast malware family detection method using control flow graphs

BooJoong Kang, Hye-Seon Kim, Taeguen Kim, Heejun Kwon, Eul Gyu Im · 2011

As attackers make variants of existing malware, it is possible to detect unknown malware by comparing with already-known malware's information. Control flow graphs have been used in dynamic analysis of program source code. In this paper, we proposed a new method which can analyze and detect malware binaries using control flow graphs and Bloom filter by abstracting common characteristics of malware families. The experimental results showed that processing overhead of our proposed method is much lower than n-gram based methods.

Read the paper · More papers on PaperTik