Malware Family Classification Based on Novel Features from Frequency Analysis
Agency for Defense Development (ADD), Daejeon, South Korea, Chang-Hee Choi, Kyeongsik Lee, Hwaseong Lee, Ilhoon Jeong, Hosang Yun · International Journal of Computer Theory and Engineering · 2018
In the past, the number of malware was small, and signature-based anti-virus program could be used to effectively protect the system.Cyber attackers create a large number of variants of malwares with automated tools to avoid signature-based anti-virus programs.Creating signature for all the variants is quite expensive task.To solve this problem, defensive side has been tried to automatically detect the malware variants.Classifying malware families can be one way to solve them.In this paper, we extract novel features from frequency analysis of malware to classify malware family.We separate the malware into section level and apply DCT/DFT to each section.Experimental results show that the proposed method can achieves high accuracy and low operation cost.