Apoyo al SGSI por Medio de la Clasificación de Malware Empleando Análisis de Patrones

Translated title of the contribution: SGSI support throught malware's classification using a pattern analysis

Mauricio Macias, Cristian Barria, Alejandra Acuna, CLAUDIO ALONSO CUBILLOS FIGUEROA

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

1 Scopus citations

Abstract

Nowadays, there are significant amounts of malware codes that are created every day. However, the majority of these samples (malware) are variations of other malware that have been already identified. Therefore, most of the analyzed malware have similar structure among them. In this investigation, we will present a technic to extract features throughout different abstraction levels in order to classify malware codes. This analysis is based on three factors: the position where the malware is detected, the functions' calls from each Dynamic Link Libraries (DLL) and the ten most frequently visited hexadecimals per each malware sample. Once those characteristics are obtained, a descriptive vector of each malware is built. This vector works as a training to different learning machines types (SVM, IBL, and Decision Tree) and as a classification of the variations of malware codes (Virus, Backdoor, Trojan, and Adware). The result in the precision of the classification was 78.38% average where 3 types of learning machines were combined. The classified type as virus and algorithm IB1 (Instance Based Learning, IBL) were considered more accurate. These results are a fundamental support to the management system in information security by combining traditional and new classification and detention techniques of malware codes.

Translated title of the contributionSGSI support throught malware's classification using a pattern analysis
Original languageSpanish
Title of host publication2016 IEEE International Conference on Automatica, ICA-ACCA 2016
PublisherInstitute of Electrical and Electronics Engineers Inc.
ISBN (Electronic)9781509011476
DOIs
StatePublished - 8 Dec 2016
Externally publishedYes
Event2016 IEEE International Conference on Automatica, ICA-ACCA 2016 - Curico, Chile
Duration: 19 Oct 201621 Oct 2016

Publication series

Name2016 IEEE International Conference on Automatica, ICA-ACCA 2016

Conference

Conference2016 IEEE International Conference on Automatica, ICA-ACCA 2016
CountryChile
CityCurico
Period19/10/1621/10/16

Fingerprint Dive into the research topics of 'SGSI support throught malware's classification using a pattern analysis'. Together they form a unique fingerprint.

Cite this