REFORM: Relevant Features for Malware Analysis
P. Vinod, Vijay Laxmi, Manoj Singh Gaur · 2012
To address the problem of detecting obfuscatedmalware we propose a non-signature based method using machine learning techniques. Mnemonic n-grams from malware and benign samples are extracted. A subset of mnemonic n-gram features are extracted using feature selection methods such as Principal Component Analysis (PCA) and Minimum Redundancy and Maximum Relevance (mRMR). These methods select prominent features that can effectively discriminate malware and benign samples. Promising results with very small features and better accuracies as compared with previous work depict that the proposed method can be effectively used for identifying malicious files.