Detailed Information

Cited 0 time in webofscience Cited 0 time in scopus
Metadata Downloads

A Novel Approach to Detect Malware Based on API Call Sequence Analysis

Authors
Ki, YoungjoonKim, EunjinKim, Huy Kang
Issue Date
2015
Publisher
SAGE PUBLICATIONS INC
Citation
INTERNATIONAL JOURNAL OF DISTRIBUTED SENSOR NETWORKS
Indexed
SCIE
SCOPUS
Journal Title
INTERNATIONAL JOURNAL OF DISTRIBUTED SENSOR NETWORKS
URI
https://scholar.korea.ac.kr/handle/2021.sw.korea/133188
DOI
10.1155/2015/659101
ISSN
1550-1329
Abstract
In the era of ubiquitous sensors and smart devices, detecting malware is becoming an endless battle between ever-evolving malware and antivirus programs that need to process ever-increasing security related data. For malware detection, various approaches have been proposed. Among them, dynamic analysis is known to be effective in terms of providing behavioral information. As malware authors increasingly use obfuscation techniques, it becomes more important to monitor how malware behaves for its detection. In this paper, we propose a novel approach for dynamic analysis of malware. We adopt DNA sequence alignment algorithms and extract common API call sequence patterns of malicious function from malware in different categories. We find that certain malicious functions are commonly included in malware even in different categories. From checking the existence of certain functions or API call sequence patterns matched, we can even detect new unknown malware. The result of our experiment shows high enough F-measure and accuracy. API call sequence can be extracted from most of the modern devices; therefore, we believe that our method can detect the malware for all types of the ubiquitous devices.
Files in This Item
There are no files associated with this item.
Appears in
Collections
School of Cyber Security > Department of Information Security > 1. Journal Articles

qrcode

Items in ScholarWorks are protected by copyright, with all rights reserved, unless otherwise indicated.

Altmetrics

Total Views & Downloads

BROWSE