New Malicious Executables Detection Based on Association Rules

Chao Chen · Jisuanji gongcheng · 2008

In order to improve the current malicious detection technology based on signature,this paper presents a method based on data mining.By researching the rules of API calling sequences during executing viruses,the method uses Apriori algorithms to extract some valuable related rules which hide out in a lot of API calling sequences of viruses.These rules can be used to detect Viruses.Experimental results validate its effection.

Read the paper · More papers on PaperTik