Classifying malicious system behavior using event propagation trees
Stefan Marschalek, Robert Luh, Manfred Kaiser, Sebastian Schrittwieser · 2015
Behavior-based analysis of dynamically executed software has become an established technique to identifying and analyzing potential malware. Most solutions rely on API or system call patterns to determine whether a sample is exhibiting malicious activity. Analysis is usually performed on demand and offers little insight into the current system state. In addition, the fixed nature of behavioral patterns is known to cause false-positives whenever a certain, potentially malicious action is used in a benign context.