Malware Detection Using Control Flow Graphs
Pradeep Kumar Tiwari · 2024
Malicious programs invade user privacy by spying on their activities, even software from well-known sources like Google or Sony might engage in undesired actions. Unfortunately, current methods for detecting malware and examining unfamiliar code have notable limitations. To tackle this issue, we propose a system that identifies and analyzes malware by capturing this essential behavior. We generated call flow graphs of the executables in each category. The CFGs from each of the know good application is accounted alongside the CFGs of the bad application. In this approach the assumption from the dataset is that the application exhibits the same behavior after each new spawn. The test application is exposed to both the call graph sequences and any deviation in the behavior the program of similar category may potentially indicate a data leakage. Our approach resulted in the detection of malwares by utilizing the CFG converted vectors as a feature for classification algorithms. We utilized the open-source dataset API-Mal Detect for our analysis which consisted of 2570 windows executables with half of them being malwares. Our technique of malware detection resulted in the detection accuracy of up to 95 %. Also, in the 527 test cases of applications, 40% cases of the data leakages were found using this technique.