• DocumentCode
    1814139
  • Title

    Generating malware signature using transcoding from sequential data to amino acid sequence

  • Author

    Yue Zhao ; Yong Tang ; Yijie Wang ; Shuhui Chen

  • Author_Institution
    Coll. of Comput., Nat. Univ. of Defense Technol., Changsha, China
  • fYear
    2013
  • fDate
    1-5 July 2013
  • Firstpage
    266
  • Lastpage
    272
  • Abstract
    Signature generation is critical for malware defense. Since the manual operation of signature generation costs too much time and does not guarantee the accuracy, the automatic signature generation has raised great concerns. In this paper, we propose a novel approach for automatic signature generation of malware, which directly leverages bioinformatics algorithms and toolkits based on transcoding. Initially, we convert the malware sequential data, like propagation dataflow, system call sequences, malicious file content, etc. into amino acid sequences by transcoding. Then we leverage multiple sequence alignment software in bioinformatics, such as CLUSTAL, T-COFFEE and MUSCLE to align amino acid sequences. Finally, based on the alignment result of the amino acid sequences, the malware sequential signatures can be obtained through an inverse transcoding procedure. In our experiments, some multiple sequence alignment software based on different algorithms are evaluated and compared for the effect and efficiency of signature generation.
  • Keywords
    bioinformatics; digital signatures; invasive software; CLUSTAL; MUSCLE; T-COFFEE; amino acid sequence; bioinformatics algorithms; inverse transcoding procedure; malicious file content; malware defense; malware sequential data; malware sequential signatures; malware signature generation; multiple sequence alignment software; propagation dataflow; system call sequences; Accuracy; Amino acids; Bioinformatics; Malware; Software; Software algorithms; Transcoding; bioinformatics; malware; multiple sequence alignment; signature generation; transcoding;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    High Performance Computing and Simulation (HPCS), 2013 International Conference on
  • Conference_Location
    Helsinki
  • Print_ISBN
    978-1-4799-0836-3
  • Type

    conf

  • DOI
    10.1109/HPCSim.2013.6641425
  • Filename
    6641425