A Dynamic Heuristic Method for Detecting Packed Malware Using Naive Bayes
Ehab M. Alkhateeb, Mark Stamp · 2019
In this paper we consider a heuristic malware detection method based on dynamic analysis of API calls. We utilize a naïve Bayes classifier to distinguish between benign and malware samples, and Levenshtein distance is shown to increase the effectiveness of the technique. For comparison, we consider commercial anti-malware products. We provide experimental evidence of the strength of our technique based on a substantial malware dataset. We show that our approach achieves particularly impressive results in detecting packed malware samples.