MALWARE DETECTION BASED ON OBJECTIVE-ORIENTED ASSOCIATION MINING

Xiao Xiao,Ding Yuxin,Zhang Yibin,Tang Ke,Dai Wei
DOI: https://doi.org/10.1109/icmlc.2013.6890497
2013-01-01
Abstract:Signature matching methods are inadequate to detect unseen malwares. In this paper an API (Application Programming Interface) based data mining method is proposed to detect unseen malwares. The data mining algorithm, objective-oriented associate mining (OOA), is employed to mine association rules for detecting malwares. To find association rules with strong discrimination power, an improved algorithm for frequent item generation is presented. In this algorithm a frequent item is evaluated by its support and its classification capability. The experiments prove that the proposed methods are effective and can be used to detect malware variants and unknown malicious executable.
What problem does this paper attempt to address?