A malware variants detection methodology with an opcode based feature method and a fast density based clustering algorithm
Cheng Wang, Zheng Kun Qin, Jixin Zhang, Hui Yin · 2016
Malware is one of the most terrible and major security threats facing the Internet today. In practice, the most widely used malware detection method is static detection. Static detection is effective for many types of malware. Operation code (opcode) sequences is one of the most important malware features for static analysis. In this paper, our goal is to optimize the accuracy and performance based on opcode features. Due to the diversity of the operation code, resulting in a large dimensions of feature of the malware, which will lead to low performance. We propose an information entropy based feature extraction method to extract a few but very useful information as representation of malware instances. At the same time, because of the low performance of the machine learning algorithm and the large set of features in the training and detection phase. We propose a generic Fast Density-Based Clustering algorithm for fast and accurately clustering malware instances. And our experiments demonstrate that our automated malware variant detection methodology is able to achieve high accuracy with significant speedup comparing with the other state-of-art approaches.