Discovering similar malware samples using API call topics

Akinori Fujino, Junichi Murakami, Tatsuya Mori

    研究成果: Conference contribution

    12 引用 (Scopus)

    抜粋

    To automate malware analysis, dynamic malware analysis systems have attracted increasing attention from both the industry and research communities. Of the various logs collected by such systems, the API call is a very promising source of information for characterizing malware behavior. This work aims to extract similar malware samples automatically using the concept of 'API call topics,' which represents a set of API calls that are intrinsic to a specific group of malware samples. We first convert Win32 API calls into 'API words.' We then apply non-negative matrix factorization (NMF) clustering analysis to the corpus of the extracted API words. NMF automatically generates the API call topics from the API words. The contributions of this work can be summarized as follows. We present an unsupervised approach to extract API call topics from a large corpus of API calls. Through analysis of the API call logs collected from thousands of malware samples, we demonstrate that the extracted API call topics can detect similar malware samples. The proposed approach is expected to be useful for automating the process of analyzing a huge volume of logs collected from dynamic malware analysis systems.

    元の言語English
    ホスト出版物のタイトル2015 12th Annual IEEE Consumer Communications and Networking Conference, CCNC 2015
    出版者Institute of Electrical and Electronics Engineers Inc.
    ページ140-147
    ページ数8
    ISBN(印刷物)9781479963904
    DOI
    出版物ステータスPublished - 2015 7 14
    イベント2015 12th Annual IEEE Consumer Communications and Networking Conference, CCNC 2015 - Las Vegas, United States
    継続期間: 2015 1 92015 1 12

    Other

    Other2015 12th Annual IEEE Consumer Communications and Networking Conference, CCNC 2015
    United States
    Las Vegas
    期間15/1/915/1/12

      フィンガープリント

    ASJC Scopus subject areas

    • Computer Networks and Communications

    これを引用

    Fujino, A., Murakami, J., & Mori, T. (2015). Discovering similar malware samples using API call topics. : 2015 12th Annual IEEE Consumer Communications and Networking Conference, CCNC 2015 (pp. 140-147). [7157960] Institute of Electrical and Electronics Engineers Inc.. https://doi.org/10.1109/CCNC.2015.7157960