Malware Classification using Early Stage Behavioral Analysis
Nitesh Kumar, Subhasis Mukhopadhyay, Mugdha Gupta, Anand Handa, Sandeep K. Shukla · 2019
In the recent years, there has been an exponential growth in the number of malware captured and analyzed by the antivirus companies. However, much of these malware are variants of already known malware. Thus, it has become necessary to determine whether a malware belongs to a known family, or exhibits a new behavior hitherto unseen, and requires further analysis. Existing traditional approaches used by antivirus companies are based on signature-based detection and can be thwarted in case of zero-day exploit-based malware. Manual examination of such executables is extremely cumbersome due to the enormous number of such cases. Also, it has become necessary to speed up the detection process and predict before the executable releases its malicious payload. In this work, we addressed the above issues using automated yet efficient malware analysis. We classified the malicious executables into different malware classes in the earliest possible time. In this work, firstly we use static approach and achieve the highest classification accuracy of 97.95% using a Random Forest classifier. Secondly, we use Dynamic approach as it provides useful insights in the case of obfuscated or packed malware where static analysis is not as effective. We achieve the highest classification accuracy of 99.13% using Random Forest classifier. Lastly, we use a combination of both the approaches to overcome the limitations of static and as well as dynamic approaches, i.e., the Hybrid approach. Our experiments achieve the highest classification accuracy of 99.74% for classifying malware into types in the initial 4 seconds of its execution using Random Forest. Our solution is robust and scalable as we have also tested our model on packed and obfuscated malware samples. The model achieves an accuracy of 96.73% and 96.31% on packed and obfuscated malware samples, respectively.