Classification of packed PE files based on data mining

Yan Hong-ping · Journal of Computer Applications · 2011

The proliferation of malicious code makes automatic malicious code detection an inevitable trend.Packed Portable Executable(PE) files identification is a necessary step of malicious code analysis.The paper presented an automatic identification method based on data mining,through which feature was extracted from PE files.The paper used classification algorithms and selected features to detect packed PE files.The test results show that the identification rate is 98.7% when using J48 classifier.

Read the paper · More papers on PaperTik