دورية أكاديمية

File Entropy Signal Analysis Combined With Wavelet Decomposition for Malware Classification

التفاصيل البيبلوغرافية
العنوان: File Entropy Signal Analysis Combined With Wavelet Decomposition for Malware Classification
المؤلفون: Hui Guo, Shuguang Huang, Cheng Huang, Zulie Pan, Min Zhang, Fan Shi
المصدر: IEEE Access, Vol 8, Pp 158961-158971 (2020)
بيانات النشر: IEEE, 2020.
سنة النشر: 2020
المجموعة: LCC:Electrical engineering. Electronics. Nuclear engineering
مصطلحات موضوعية: Malware classification, entropy sequences, signal processing, Haar wavelet transform, support vector machine, Electrical engineering. Electronics. Nuclear engineering, TK1-9971
الوصف: With the rapid development of the Internet, malware variants have increased exponentially, which poses a key threat to cyber security. Persistent efforts have been made to classify malware variants, but there are still many challenges, including the incapacity to deal with various malware variants belonging to similar families, the problem of time and resource consuming, etc. This paper proposes a novel method, called Malware Entropy Sequences Reflect the Family (MESRF), to improve the classification of malware based on the entropy sequences features. In prior research, entropy demonstrated good performance in many areas. First, the global features of the signals were extracted from the entropy sequences by some statistical methods. Next, some local features (i.e. structural entropy features) are extracted based on the discrete wavelet decomposition algorithm and vectorized by the Bag-of-words model, endowing it the high accuracy of malware classification. To evaluate our method, we conducted numerous experiments on the malware datasets with more than 20,000 samples. Through experiments, MESRF showed superiority comparing with other malware classification models, and the accuracy and ROC of the method even could reach 99.83% and 99.98% respectively on the malimg dataset.
نوع الوثيقة: article
وصف الملف: electronic resource
اللغة: English
تدمد: 2169-3536
Relation: https://ieeexplore.ieee.org/document/9180349/; https://doaj.org/toc/2169-3536
DOI: 10.1109/ACCESS.2020.3020330
URL الوصول: https://doaj.org/article/782b04f18e754a419c04f5391cf59aec
رقم الأكسشن: edsdoj.782b04f18e754a419c04f5391cf59aec
قاعدة البيانات: Directory of Open Access Journals
الوصف
تدمد:21693536
DOI:10.1109/ACCESS.2020.3020330