Evaluation on Malware Classification by Combining Traffic Analysis and Fuzzy Hashing of Malware Binary
Shohei Hiruta, Yukiko Yamaguchi, Hajime Shimada, Hiroki Takakura · IEICE Technical Report; IEICE Tech. Rep. · 2015
Recent cyber attacks frequently use variants of malware programs which update existing functions drastically and implement new functions. Not only in functional viewpoint, recent malware programs improves their secrecy in variants, such as obfuscation, encryption, and changing thair behavior by inspecting their execution environment. But the number of skilled malware analysts is limited. So, a method to reduce expensive cost of manual analysis is widely explored in order to fight against huge amounts of malware programs. In this paper, we propose an integrated approach of dynamic traffic analysis and static program analysis. Similar to other conventional methods, the former part performs feature extraction, clustering, and labeling to summerize traffic data into sequence of characters. The latter part applies Fuzzy Hashing to malware programs which can effectively represent identical partial part in malware programs. We evaluated three integration patterns such as prioritize dynamic analysis result, prioritize static analysis result, and utilize mean of two analysis result. From the experimental results by using 340 malware samples and their traffic data, our method can correctly identify 61.1% of malware.