Skip to main content

Method of Detecting Malware Through Analysis of Opcodes Frequency with Machine Learning Technique

  • Conference paper
  • First Online:

Part of the book series: Lecture Notes in Electrical Engineering ((LNEE,volume 421))

Abstract

As the evolution of malware, vast damages are occurred in various industry fields. For this reason, research on malware detection has conducted actively. To improve the security of the network, SDN Quarantined Network (SQN) has been proposed. In this paper, we developed one of malware detection modules in first quarantine station in SQN by using the fact that benign and malicious files have different opcode frequency. And we applied machine learning technique as different way compare to conventional method. we verified that our module is valuable as one of detection modules and our final aim is to mount this module on the SQN system. Therefore, it would be possible more accurate inspection for new type of security attack with multiple detection modules.

This is a preview of subscription content, log in via an institution.

Buying options

Chapter
USD   29.95
Price excludes VAT (USA)
  • Available as PDF
  • Read on any device
  • Instant download
  • Own it forever
eBook
USD   169.00
Price excludes VAT (USA)
  • Available as EPUB and PDF
  • Read on any device
  • Instant download
  • Own it forever
Softcover Book
USD   219.99
Price excludes VAT (USA)
  • Compact, lightweight edition
  • Dispatched in 3 to 5 business days
  • Free shipping worldwide - see info
Hardcover Book
USD   219.99
Price excludes VAT (USA)
  • Durable hardcover edition
  • Dispatched in 3 to 5 business days
  • Free shipping worldwide - see info

Tax calculation will be finalised at checkout

Purchases are for personal use only

Learn about institutional subscriptions

References

  1. Nath, H.V., Mehtre, B.M.: Static malware analysis using machine learning methods. In: Martínez Pérez, G., Thampi, S.M., Ko, R., Shu, L. (eds.) SNDS 2014. CCIS, vol. 420, pp. 440–450. Springer, Heidelberg (2014). doi:10.1007/978-3-642-54525-2_39

    Chapter  Google Scholar 

  2. Bilar, D.: Opcodes as predictor for malware. Int. J. Electron. Secur. Digital Forensics 1(2), 156 (2007)

    Article  Google Scholar 

  3. Santos, I., Brezo, F., Sanz, B., Laorden, C., Bringas, P.: Using opcode sequences in single-class learning to detect unknown malware. IET Inf. Secur. 5(4), 220 (2011)

    Article  Google Scholar 

  4. Shabtai, A., Moskovitch, R., Feher, C., Dolev, S., Elovici, Y.: Detecting unknown malicious code by applying classification techniques on OpCode patterns. Secur. Inf. 1(1), 1 (2012)

    Article  Google Scholar 

  5. Santos, I., Brezo, F., Ugarte-Pedrero, X., Bringas, P.: Opcode sequences as representation of executables for data-mining-based unknown malware detection. Inf. Sci. 231, 64–82 (2013)

    Article  MathSciNet  Google Scholar 

  6. Santos, I., Nieves, J., Bringas, P.: Semi-supervised learning for unknown malware detection. In: Abraham, A., Corchado, J.M., González, S.R., De Paz Santana, J.F. (eds.) International Symposium on DCAI. AISC, vol. 91, pp. 415–422. Springer, Heidelberg (2011)

    Google Scholar 

  7. Decision Trees – scikit-learn 0.17.1 documentation. http://scikit-learn.org/stable/modules/tree.html

  8. Vxheaven.org. Welcome to VX Heaven! (2016). http://vxheaven.org/

Download references

Acknowledgements

This research was supported by Basic Science Research Program through the National Research Foundation of Korea (NRF) funded by the Ministry of Education (NRF-2010-0020210).

This work was supported by Institute for Information & communications Technology Promotion (IITP) grant funded by the Korea government (MSIP) (No.R0113-15-0002, Automotive ICT based e-Call standardization and after-market device development).

Author information

Authors and Affiliations

Authors

Corresponding author

Correspondence to Sang-Uk Woo .

Editor information

Editors and Affiliations

Rights and permissions

Reprints and permissions

Copyright information

© 2017 Springer Nature Singapore Pte Ltd.

About this paper

Cite this paper

Woo, SU., Kim, DH., Chung, TM. (2017). Method of Detecting Malware Through Analysis of Opcodes Frequency with Machine Learning Technique. In: Park, J., Pan, Y., Yi, G., Loia, V. (eds) Advances in Computer Science and Ubiquitous Computing. UCAWSN CUTE CSA 2016 2016 2016. Lecture Notes in Electrical Engineering, vol 421. Springer, Singapore. https://doi.org/10.1007/978-981-10-3023-9_158

Download citation

  • DOI: https://doi.org/10.1007/978-981-10-3023-9_158

  • Published:

  • Publisher Name: Springer, Singapore

  • Print ISBN: 978-981-10-3022-2

  • Online ISBN: 978-981-10-3023-9

  • eBook Packages: EngineeringEngineering (R0)

Publish with us

Policies and ethics