Automated malware classification based on network behavior

93Citations
Citations of this article
117Readers
Mendeley users who have this article in their library.
Get full text

Abstract

Over the past decade malware, i.e., malicious software, has become a major security threat on the Internet. Today anti-virus companies receive thousands of malicious samples every day. However the vast majority of these samples are variants of the existing malware. Due to the sheer number of malware variants it is important to accurately determine whether a sample belongs to a known malware family or exhibits a new behavior and thus requires further analysis and separate detection signature. Despite of the importance of network activity, the existing research on malware analysis does not fully leverage the malware network behavior for classification. In this paper, we propose an automated malware classification system that focuses on network behavior of malware samples. Our approach employs behavioral profiles that summarize the network behavior of malware samples. The proposed approach is applied to a real world malware corpus. Our experimental results show the effectiveness of the proposed approach in classifying malware samples only based on the network activity exhibited by the samples. © 2013 IEEE.

Cite

CITATION STYLE

APA

Nari, S., & Ghorbani, A. A. (2013). Automated malware classification based on network behavior. In 2013 International Conference on Computing, Networking and Communications, ICNC 2013 (pp. 642–647). https://doi.org/10.1109/ICCNC.2013.6504162

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free