A Novel Approach to Malware Detection using Static Classification
Sanjam Singla, Divya Bansal, Ekta Gandotra, Sanjeev Sofat · 2015
Malware, commonly called computer virus, is one of the top security threats to the computer systems around the globe. These are evolving at a very rapid pace and are continually finding new ways to exploit and infect the systems of various enterprises and businesses. Malwares use different techniques to camouflage themselves to make their lifetime longer. In this paper, we present a simple technique based on static features extracted from Windows PE files. The features used are not only extracted from the header part of the malware but also from the payload i.e. body of malware. The static features used are a combination of Function Call Frequency and Opcode Frequency for differentiating malwares from clean files. This combination of features set makes it a new approach for malware detection which provides an accuracy of 97% for a dataset of 1,230 executables files including 800 malware and 430 cleanwares. For classification purpose, we use machine learning algorithms available in WEKA library. Based on the results obtained, we conclude that both features considered in this work play a significant role in distinguishing malicious files from clean ones. KeywordsStatic Malware Analysis; Machine Learning; Classification;