Unsupervised behavioural mining and clustering for malware family identification

Khanh Huu The Dam, Thomas Given-Wilson, Axel Legay · 2021

More accurate and advanced detection and classification of malware requires exploiting program behaviour and not merely syntactic or static features. One approach is to use system call dependency graphs (SCDGs) that represent the program behaviour by interactions with the system, and the relations between these interactions. These SCDGs have been used with supervised learning techniques to very accurately detect and classify malware. This works considers the unsupervised learning challenge of mining for common clusters of behaviour without a priori knowledge. This allows for clustering of similar programs by behaviour, that can then be used for either classification or further analysis.

Read the paper · More papers on PaperTik