CQUniversity
Browse

A fast flowgraph based classification system for packed and polymorphic malware on the endhost

Version 2 2022-04-07, 02:20
Version 1 2017-12-06, 00:00
conference contribution
posted on 2022-04-07, 02:20 authored by Silvio Cesare, Yang Xiang
Identifying malicious software provides great benefit for distributed and networked systems. Traditional real-time malware detection has relied on using signatures and string matching. However, string signatures ineffectively deal with polymorphic malware variants. Control flow has been proposed as an alternative signature that can be identified across such variants. This paper proposes a novel classification system to detect polymorphic variants using flowgraphs. We propose using an existing heuristic flowgraph matching algorithm to estimate graph isomorphisms. Moreover, we can determine similarity between programs by identifying the underlying isomorphic flowgraphs. A high similarity between the query program and known malware identifies a variant. To demonstrate the effectiveness and efficiency of our flowgraph based classification, we compare it to alternate algorithms, and evaluate the system using real and synthetic malware. The evaluation shows our system accurately detects real malware, performs efficiently, and is scalable. These performance characteristics enable real-time use on an intermediary node such as an Email gateway, or on the endhost.

Funding

Category 1 - Australian Competitive Grants (this includes ARC, NHMRC)

History

Start Page

721

End Page

728

Number of Pages

8

Start Date

2010-04-20

Finish Date

2010-04-23

ISBN-13

9780769540191

Location

Perth, Western Australia

Publisher

IEEE

Place of Publication

Los Alamitos, CA

Peer Reviewed

  • Yes

Open Access

  • No

External Author Affiliations

Centre for Intelligent and Networked Systems (CINS); Institute for Resource Industries and Sustainability (IRIS);

Era Eligible

  • Yes

Name of Conference

24th International Conference on Advanced Information Networking and Applications Workshops/Symposia

Parent Title

Proceedings, 24th IEEE International Conference on Advanced Information Networking and Applications

Usage metrics

    CQUniversity

    Exports

    RefWorks
    BibTeX
    Ref. manager
    Endnote
    DataCite
    NLM
    DC