Fingerprinting Malware using Bioinformatics Tools Building a Classifier for the Zeus Virus

نویسندگان

  • Jay Pedersen
  • Dhundy Bastola
  • Ken Dick
  • Robin Gandhi
  • William Mahoney
چکیده

This paper describes an exploratory research project which creates a classifier to distinguish artifacts containing content specific to a known computer virus, given a training set of samples of variants of that virus and using local alignments between the artifacts as its information source. A bioinformatics tool, BLAST, finds the local alignments between a digital artifact and a repository of representatives of the virus. The classification is driven by a comparison of the local alignments to determined alignment fingerprints of the virus representatives. Project methods include the creation of “synthetic DNA” representations of digital artifacts, representative selection for a set of computer viruses, alignment fingerprint creation for those representatives, and using the representatives, fingerprints and alignments in a classification scheme. The project examined Zeus Trojan viruses and had a 91% correct identification rate of verified Zeus viruses and a 3% false positive rate.

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

MAPPING THE LAWS WHICH APPLY TO INTERCEPTING WIRELESS COMMUNICATIONS IN A WESTERN AUSTRALIAN LEGAL CONTEXT The rapid evolution and deployment of WiFi

The prevalence of Android smartphones and the immense growth of Android malware create significant numbers of malware incidents that require forensics handling. Certain smartphone forensic tool has incorporated anti-virus databases in their device for malware detection process. However, examiners should be aware that most of anti-virus application uses known patterns or signatures for malware d...

متن کامل

Polymorphic malware detection using sequence classification methods and ensembles

Identifying malicious software executables is made difficult by the constant adaptations introduced by miscreants in order to evade detection by antivirus software. Such changes are akin to mutations in biological sequences. Recently, high-throughput methods for gene sequence classification have been developed by the bioinformatics and computational biology communities. In this paper, we apply ...

متن کامل

Malware Detection using Classification of Variable-Length Sequences

In this paper, a novel method based on the graph is proposed to classify the sequence of variable length as feature extraction. The proposed method overcomes the problems of the traditional graph with variable length of data, without fixing length of sequences, by determining the most frequent instructions and insertion the rest of instructions on the set of “other”, save speed and memory. Acco...

متن کامل

Detection of Malware to Enhance the Network Accuracy using Ensemble based Classifier

Detection of malware is a complex process. Many developers face problem in detecting the malware. The Malware is program or software that damages the computer system. Malicious Software is “any code added, changed, or removed from a software system to intentionally cause harm or subvert the system’s intended function”. Malware is a type of intrusion in the computer network. Excellent technology...

متن کامل

A Malware Homologous Analysis Method Based on Sequence of System Function

The methodology of homology analysis for malware can be used to estimate the phylogeny of malware samples. This paper proposes a malware homology analysis method based on sequence of system function, which is used to solve the problem of universal evolution of malware samples with the help of the bioinformatics tools. The results show that our method can not only be taken as an evolution analys...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2013