Indexed by:
Abstract:
With the rapid development of cloud computing, cloud security is increasingly an important issue. Virtual machine (VM) is the main form to provide cloud service. To protect VMs against malware attack, a cloud needs to have the ability to react not only to known malware, but also to the new emerged ones. Virtual Machine Introspection (VMI) is a good solution for VM monitoring, which can obtain the raw memory state of the VM at Virtual Machine Monitor (VMM) level. Through analyzing the memory dumps, the significant features of malware can be obtained. In our research, we propose a novel static analysis method for unknown malware detection based on the feature of opcode n-gram of the executable files. Different feature sizes ranging from 2-gram to 4-gram are implemented with the feature length of 100, 200, 300 respectively. The feature selection criterion of Term Frequency (TF)-Inverse Document Frequency (IDF) and Information Gain (IG) are leveraged to extract the top features for classifier training. Different classifiers are trained with the preprocessed dataset. The experimental results show that the weighted integrated classifier with opcode 4-gram of 300 features has the optimal accuracy of 98.2%. © 2018, Springer Nature Switzerland AG.
Keyword:
Reprint Author's Address:
Email:
Source :
ISSN: 0302-9743
Year: 2018
Volume: 10989 LNAI
Page: 717-726
Language: English
Cited Count:
WoS CC Cited Count: 0
SCOPUS Cited Count: 2
ESI Highly Cited Papers on the List: 0 Unfold All
WanFang Cited Count:
Chinese Cited Count:
30 Days PV: 16