Behavior detection of malware based on combination of API function and its parameters
Han Lan-shen · Jisuanji yingyong yanjiu · 2013
This paper proposed a more flexible and scalable method,which was based on more detailed operation characteristics: API function call name,input parameters in API functions,the two types of the combination of features. It extracted three categories above,defined the concept of the information gain value of malicious code with the help of the entropy in information theory,then,calculated the information gain value of the corresponding API and its parameters in distinguishing the malware and begin software. And then selected the characteristic having higher recognition rate to reduce the number of features and analysis time. Experiment show that,a small amount of feature selection and higher accuracy makes it more superior to the algorithm of API based detection of malware.