Malicious Code Family Tagging based on Malicious Code Image Fingerprint

Shuai HE,Jia-yong LIU
DOI: https://doi.org/10.3969/j.issn.1002-0802.2017.03.028
2017-01-01
Abstract:Along with the fast development of the internet, malware grows rapidly in number, and many malicious samples are just variations of previously-encountered samples. By studing the image features of malicious code, the malicious code family tagging based on malicious code image fingerprint is proposed. This method draws the disassembled malicious code file of malicious code as image, extracts GIST feature and SIFT feature and optimizes them with BoW model. The random forests algorithm is applied to classifying the extracted features. The experimental results indicate that this method is effective for tagging the malicious code family and has high tagging precision and low false-reporting rate.
What problem does this paper attempt to address?