Implementation of Intelligent Malware Detection System Using Post Processing Techniques
Shrikant Kokate, Shreyash Salunke · 2017
The Malware is program/software that damages or affects the computer system. Nowadays all the fields are computerized. So the valuable data is stored in computer. If the malware attacks the system then there may be chances of loss of data. Therefore it is very essential to provide security to system against Malware. In this system we are going to implement detection of Malware in the system. Input given to system is virus files in executable form. These files are called as Gray List. The Gray List is obtained from Internet i.e. downloaded virus samples. Then we generate the data set from virus samples in CSV format which consists of API Sequence of sample malware files. Data set is created in CSV format because the input given to module (i.e. Rule Generation) in order to generate rules must be in CSV format. Then the Association Rules are generated by providing minimum support and confidence values. As Association Rules are generated we apply Post Processing Technique on Rules. Post Processing Technique consist of 1) Rule Pruning Rule 2) Rule Ranking 3) Rule Selection modules. After applying Post Processing Technique detection report is presented to user. Data set is generated by scanning code section of virus file, then sequence in which API functions are called are noted down. Association Rules are generated from API sequences. All Rules generated in Rule Generation module are not meaningful. Rules that are not significant for further processing are pruned in Rule Pruning module. In order to prune rule we calculate Chi-Square value of rule. After pruning, remaining rules are sorted according to Chi-Square value in Rule Ranking module. Finally Best K Rule is selected in Rule Selection module.