 |  |  | |  |  |  |  |  | | |  |  |  |
| Automated Classification and Analysis of Internet Malware | | by Michael Bailey, Jon Oberheide, Jon Andersen, Z. Morley Mao,Farnam Jahanian, Jose Nazario | AUTHORS' DESCRIPTION
In this paper, we examine the ability of existing host-based anti-virus products to provide semantically meaningful information about the malicious software and tools (or malware) used by attackers. Using a large, recent collection of malware that spans a variety of attack vectors (e.g., spyware, worms, spam), we show that different AV products characterize malware in ways that are inconsistent across AV products, incomplete across malware, and that fail to be concise in their semantics. To address these limitations, we propose a new classification technique that describes malware behavior in terms of system state changes (e.g., files written, processes created) rather than in sequences or patterns of system calls. To address the sheer volume of malware and diversity of its behavior, we provide a method for automatically categorizing these profiles of malware into groups that reflect similar classes of behaviors and demonstrate how behavior-based clustering provides a more direct and effective way of classifying and analyzing Internet malware.
Read the full article
|
DONATION: www.anti-keylogger.org and www.keylogger.org is an independent research projects supported by a team of enthusiasts. If you find this project useful and would like to help foster its continued development, please consider making a donation.  Thanks in advance for your support! |
|  |  |
|
|    |
|  | |  |  |
|  |