MDBA: Detecting Malware based on Bytes N-Gram with Association Mining

Bowei Li, Yongzheng Zhang, Junliang Yao, Tao Yin · 2019

Malware has always threatened the security of networks and computer systems. The traditional methods for malware detection are signature-based with manually designed rules. Some recent methods involving static or dynamic analysis require professional tools to extract features, while feature engineering is time-consuming and labor-intensive. In this paper, we propose MDBA, the Malware Detection based on Association mining method. Our approach only takes bytes n-grams from PE binaries as features, which can be easily obtained. By mining the n-gram features, we can produce association rules that satisfy the minimum support and the minimum confidence constraints. Based on the association rules, a classifier is built to detect whether a PE executable is malicious or not. To demonstrate the capability of our MDBA approach, we organize a large dataset with more than 10,000 PE files and conduct series of experiments on the dataset. The results show that our approach not only achieves high performance of malware detection, but also is capable of discovering malware of unknown types.

Read the paper · More papers on PaperTik