DocumentCode :
3571621
Title :
Research on Malicious Code Detection Based on Least-squares Estimation
Author :
Wu Yunlong ; Chen, Chen ; Wang Huiquan ; Xu Xinhai ; Zhou Jie
Author_Institution :
Nat. Lab. for Parallel & Distrib. Process., Nat. Univ. of Defense Technol., Changsha, China
Volume :
2
fYear :
2012
Firstpage :
124
Lastpage :
128
Abstract :
Malicious code detection based on behaviors is the development direction of anti-virus techniques. However, the current detection methods based on this theory expose several problems such as the unclearness of behavior sequence analysis and the high false negatives. For this situation, this paper proposes a malicious code detection method based on least-squares estimation. In this method, it correlates program behaviors with time and subject-object, and then constitutes an accurate and complete behavior sequence. It can provide a preprocessing method for the subsequent detection. In order to improve the accuracy and intelligence of malicious code detection, we introduce the concept of expert subjective degree. By modeling malicious samples based on least-squares estimation we can train the Expert Subjective Degree Vector (ESDV) and simulate experts to judge the threat values of malicious codes. Experiments show that this method is more accurate than the current ways to detect the malicious codes which execute themselves in sub-period and sub-process ways, so it can be used as an effective complement of the current anti-virus software.
Keywords :
computer viruses; least squares approximations; ESDV; antivirus software; behavior sequence analysis; expert subjective degree vector; high false negatives; least-squares estimation; malicious code detection method; preprocessing method; program behavior correlation; Computers; Correlation; Equations; Estimation; Libraries; Mathematical model; Monitoring; behavior correlation; expert subjective degree vector; malicious code detection; threat judging;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Computer Science and Electronics Engineering (ICCSEE), 2012 International Conference on
Print_ISBN :
978-1-4673-0689-8
Type :
conf
DOI :
10.1109/ICCSEE.2012.343
Filename :
6187981
Link To Document :
بازگشت