Automated intelligent multinomial classification of malware species using dynamic behavioural analysis

Andrii Shalaginov, Katrin Franke · 2016

Malware detection has been widely explored in recent years due to an increased rate of information theft, ransom demands and money laundering cases. It is known that MS Windows Operating System family is susceptible to attacks due to the extensive number of found vulnerabilities across many outdated versions that are still in use. As a result, multiple malware categories and families have emerged. Many researchers stress the importance of multinomial malware classification rather than conventional malicious versus benign classification. However, multinomial detection has been neither sufficiently explored nor tested on recent malware samples. We believe that dynamic analysis can reveal information more relevant to classification characteristics in each malware category, and that cannot be done by static analysis. In this ongoing research, we explore a novel application of Machine Learning classification on a multinomial malware using behavioural analysis in a controlled environment. A novel dataset containing recent malware samples was used to show a prospective application of the automated multinomial malware detection using different artifacts left in the system. Corresponding methodology was proposed to extract characteristics from the system artifacts. We believe that this work can facilitate a decision support when it is critical to narrow down the threat vectors and to find similarity in dealing with zero-day attacks.

Read the paper · More papers on PaperTik