Classifying malwares for identification of author groups

Jiwon Hong, Sanghyun Park, Sang‐Wook Kim, Dongphil Kim, Won-Ho Kim · Concurrency and Computation Practice and Experience · 2017

Summary Malwares are growing exponentially in number, and authors of malwares are continuously releasing new ones. Malwares developed by the same author group might have similar signatures. For a number of applications including digital forensic and law enforcement, such characteristics can be used to determine which author group is likely to have released a given malware. In this paper, we describe a new type of classification that identifies which group of authors is most likely to have developed a given malware. We identify and verify a set of various features obtained through static and dynamic analyses of malwares and exploit them for classification. We evaluate our approach through extensive experiments with a real‐world dataset labeled by a group of domain experts. The results show that our approach is effective and provides good accuracy in malware classification.

Read the paper · More papers on PaperTik