An Algorithmic Framework for Malicious Software Detection Exploring Structural Characteristics of Behavioral Graphs

Alvaro Chysi, Stavros D. Nikolopoulos, Iosif Polenakis · 2020

In this paper, we present the development of an algorithmic framework for the behavioral detection of malicious software utilizing a set of measurements to explore the structural characteristics of behavioral graphs. We first present the construction of the Group Relation Graphs produced by a specific type of behavioral graphs, the so called System-call Dependency Graphs obtained through taint-analysis after the execution of a malicious sample. Then, we discuss the utilization of a set of measurements applied to compute the structural characteristics of Group Relation Graphs, namely the application of the Page Rank algorithm on such graphs and the Betweeness Centrality on the vertices of the graph. We present the architecture of our proposed framework and how we deploy the computation of similarity metrics in order to measure the closeness between such characteristics exhibited among malicious and benign samples in order to perform the malware detection process. Finally, we proceed to a series of experiments in order to evaluate through five-fold cross validation the detection ability of our proposed model and prove its potentials against a set of System-call Dependency Graphs to distinguishing malicious from benign software samples.

Read the paper · More papers on PaperTik