Journal of Systems Engineering and Electronics ›› 2012, Vol. 34 ›› Issue (8): 1735-1740.
Previous Articles Next Articles
MIAO Qi-guang, WANG Yun, CAO Ying, LIU Wen-chuang
Online:
Published:
Abstract:
A malware detection method based on minimum behavior is proposed. Minimum behavior is defined as application programming interface (API) subsets which the malicious code operates on each resource at runtime. A malicious software (malware) detecting system based on minimum behavior is implemented to dynamically capture the system calls, and construct the signature of malware by extracting the defined use (def-use) relation between systems calls, and then detect the malware using a chisquare test algorithm. Compared with the method based on the frequency of API, the proposed method has a higher true positive fraction, and the false positive fraction is lower.
MIAO Qi-guang, WANG Yun, CAO Ying, LIU Wen-chuang. Research on detecting technology of malicious software based on sub-behavior[J]. Journal of Systems Engineering and Electronics, 2012, 34(8): 1735-1740.
0 / / Recommend
Add to citation manager EndNote|Reference Manager|ProCite|BibTeX|RefWorks
URL: https://www.sys-ele.com/EN/
https://www.sys-ele.com/EN/Y2012/V34/I8/1735