Technique of Detecting Malicious Executables Via Behavioral and Binary Signatures

LI Hua,LIU Zhi,QIN Zheng,ZHANG Xiao-song
DOI: https://doi.org/10.3969/j.issn.1001-3695.2011.03.094
2011-01-01
Abstract:This paper proposed a new approach that could effectively detect and restrict(unknown) malware,and implemented a prototype system.First,used support vector machine to build classifier,which could judge whether a program was malicious or not,and extracted the malware's signature.Agents running in host could detect malware and stop its execution.To analyze precise behaviors,put samples in virtual machines for executions.Experiment results show compared with naive Bayes and decision tree,our system yields low false positives as well false negatives,and the distributed architecture accelerates restriction.
What problem does this paper attempt to address?