Using multi-features to reduce false positive in malware classification
Xinjian Ma, Biao Qi, Wu Yang, Jianguo Jiang · 2016 IEEE Information Technology, Networking, Electronic and Automation Control Conference · 2016
Because of the rapid increasing of malware, one of the main challenges in malware detection is how to do malware classification automatically. Although there are many automatic classification methods recently, their results still get high false positive rate. Since the base number of malware samples is huge, a very small false positive can cause a big number of false alarms. Essentially, high false positive rate is usually caused by the adoption of obfuscation and evasion technology by malware. As a result, one or more features would be disguised. In this paper, we propose one method using multi-features to mitigate the effect of disguised features. Through this method, each kind of features is extracted independently, and used to train one classifier respectively. The system adopts the prediction if and only if the output of each classifier is the same. To test our method, we use both static and dynamic features to classify 282 samples. The experiment result shows that this method could improve the accuracy of malware classification and achieve nearly no false positive.