Toward an Approach on Probability Distribution for Polymorphic Malware Analysis
Le-Minh Nguyen, Ngoc Ha, Minh, Nguyen, Thien Binh, Tho Quan · Open Journal Systems (Global Science & Technology Forum) · 2016
Nowadays, computer security is a serious issuewhich attracts the interest from many nations. To identifymalware, most of industry approaches still center the well-knowntechnique of signature matching. However, modern polymorphicmalwares use packer to obfuscate their malicious actions. Asophisticated packer can generate virtually variants of a viralcode, making the signature-based technique easily defeated.Naturally, applying stochastic approach prompts a potentialsolution to handle polymorphic virus. This paper studies anapproach of applying probability distribution for tackling thetwo important problems in analyzing polymorphic malware,which are to identify a potential malware and to detect packerwhich malware adopts. For the first goal, we derive a newfrequency-based weight to identify most specific instructions foreach malware family, known as instruction frequency-inversemalware frequency (°) . For the second one, we propose anew term, obfuscation technique frequency-inverse packerfrequency (°) for evaluating the importance of obfuscationtechniques in packers. We have performed the experiment on4194 real malware and the result is very promising.