File Checker: Determining Behavioural Signatures of an Executable Binary to Detect Malware

R. Harshal, Himanshu Shukla, A. Jothimani, Anurag Ambroz Singh · International Journal of Computer Applications · 2020

The increasing dependency in this technologically advancing world on data is making us vulnerable to frequent cyberattacks.This study aims at classifying executable binaries(Portable Executable files) based on its run-time behaviour.Traditional approaches to detecting windowsbased malware include comparing files hashes, strings, etc., which clearly failed to detect the new world malware kindsmorphed and obfuscated.Although the dynamically based detection distinctly outperformed static based detection techniques, it failed to effectively detect advanced malicious programs.System-call injection attacks usually inject irrelevant calls to alter an execution sequence of malware, thereby making it undetectable to calls based detection systems.The proposed method aims at extracting traces of API calls made to generate possible unique alternative traces in order to detect other malicious API patterns which may be left out due to prevent call injection attacks.A classification model is built by employing the RandomForest algorithm, and its efficiency is compared with other baseline classifiers.This model classifies the data effectively with 91.9% accuracy.

Read the paper · More papers on PaperTik