Several static analysis studies have reported Machine Learning (ML) methods to detect metamorphic malware – an obfuscation technique – originating from a large family of malware variants by employing as input data features either sequences of opcodes or Portable Executable (PE) file sections. However, ML classification methods for detecting metamorphic malware using both input data features simultaneously remain to be achieved. Using a two-stage solution ML approach; this article shows that it is possible to use both sets of features without their combined contribution affecting the final outcome, but rather enhancing it. In stage 1, using sequences of opcodes; a discrete Hidden Markov Model (dHMM) validates the input data set; while stage 2 uses the PE file sections as features of a Random Forest (RF) for classification purposes and metamorphic malware detection. This hybrid approach provided promising results even though the size of the input data was not considerably large.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

A Hybrid Machine Learning Method for Detecting Metamorphic Malware

  • Victor Manuel Gonzalez-Gorrín,
  • Josep Prieto-Blázquez,
  • Joan Arnedo-Moreno

摘要

Several static analysis studies have reported Machine Learning (ML) methods to detect metamorphic malware – an obfuscation technique – originating from a large family of malware variants by employing as input data features either sequences of opcodes or Portable Executable (PE) file sections. However, ML classification methods for detecting metamorphic malware using both input data features simultaneously remain to be achieved. Using a two-stage solution ML approach; this article shows that it is possible to use both sets of features without their combined contribution affecting the final outcome, but rather enhancing it. In stage 1, using sequences of opcodes; a discrete Hidden Markov Model (dHMM) validates the input data set; while stage 2 uses the PE file sections as features of a Random Forest (RF) for classification purposes and metamorphic malware detection. This hybrid approach provided promising results even though the size of the input data was not considerably large.