DocumentCode
1814139
Title
Generating malware signature using transcoding from sequential data to amino acid sequence
Author
Yue Zhao ; Yong Tang ; Yijie Wang ; Shuhui Chen
Author_Institution
Coll. of Comput., Nat. Univ. of Defense Technol., Changsha, China
fYear
2013
fDate
1-5 July 2013
Firstpage
266
Lastpage
272
Abstract
Signature generation is critical for malware defense. Since the manual operation of signature generation costs too much time and does not guarantee the accuracy, the automatic signature generation has raised great concerns. In this paper, we propose a novel approach for automatic signature generation of malware, which directly leverages bioinformatics algorithms and toolkits based on transcoding. Initially, we convert the malware sequential data, like propagation dataflow, system call sequences, malicious file content, etc. into amino acid sequences by transcoding. Then we leverage multiple sequence alignment software in bioinformatics, such as CLUSTAL, T-COFFEE and MUSCLE to align amino acid sequences. Finally, based on the alignment result of the amino acid sequences, the malware sequential signatures can be obtained through an inverse transcoding procedure. In our experiments, some multiple sequence alignment software based on different algorithms are evaluated and compared for the effect and efficiency of signature generation.
Keywords
bioinformatics; digital signatures; invasive software; CLUSTAL; MUSCLE; T-COFFEE; amino acid sequence; bioinformatics algorithms; inverse transcoding procedure; malicious file content; malware defense; malware sequential data; malware sequential signatures; malware signature generation; multiple sequence alignment software; propagation dataflow; system call sequences; Accuracy; Amino acids; Bioinformatics; Malware; Software; Software algorithms; Transcoding; bioinformatics; malware; multiple sequence alignment; signature generation; transcoding;
fLanguage
English
Publisher
ieee
Conference_Titel
High Performance Computing and Simulation (HPCS), 2013 International Conference on
Conference_Location
Helsinki
Print_ISBN
978-1-4799-0836-3
Type
conf
DOI
10.1109/HPCSim.2013.6641425
Filename
6641425
Link To Document