Title :
Reduction of malicious behavior patterns based on attribute order
Author :
Sun, Xiaoyan ; Guo, Ning ; Zhu, Yuefei
Author_Institution :
Zhengzhou Inf. Sci. & Technol. Inst., Zhengzhou, China
Abstract :
In the field of malware study, the automatic generation of malicious behavior pattern based on system call trace is important to malware detection. This paper studied the generation of malicious behavior distinguishing pattern, and used attributes order reduction method to reduce the patterns. It gave the ordering rules based on mutual information and the size of pattern. After studying the quick reduction algorithm based on divide and conquer method, it improved the algorithm according to the characteristic of datasets. Finally, test results verifies that the improved algorithm can decrease the reduction time, the ordering method can obtain relatively good reduction results, and the classification result is relatively good.
Keywords :
data reduction; invasive software; attributes order reduction; malicious behavior pattern automatic generation; malicious behavior pattern reduction; malware detection; system call trace; Attribute Order; Attributes Reduction; Distinguishing Pattern; Malicious behavior; Malware;
Conference_Titel :
Intelligent Computing and Intelligent Systems (ICIS), 2010 IEEE International Conference on
Conference_Location :
Xiamen
Print_ISBN :
978-1-4244-6582-8
DOI :
10.1109/ICICISYS.2010.5658544