APT Malware Classification Method Based on Feature Fusion

Liang He, Chao Li, Xin Li, Shouzhi Jiang · 2021 International Conference on Computer Information Science and Artificial Intelligence (CISAI) · 2021

In order to classify the malwares used in APT attack, this paper proposes a feature fusion based classification method for APT malwares. Firstly, the Entry Point, Dynamic Link Library, Resource Language, the Number of Sections and the Number of Resources of malware used in APT attack are extracted as features, and then they are fused to form fusion features. Next, Random Forest algorithm is used to train. Finally, the model of single feature and multi-class feature combination models are constructed to compare the classification ability and effect of fusion features. In this paper, 2862 APT malware samples from 12 APT families are used. The experimental results show that the accuracy of the classification by using random forest algorithm is 93.48% under the fusion of 5 types of features, which is better than other classification models.

Read the paper · More papers on PaperTik