Improving Malware Classification: Bridging the Static/Dynamic Gap
Vinit Singh 18th April 2017
Authors: Blake Anderson, Curtis Storlie, Terran Lane
CISC850 Cyber Analytics
Improving Malware Classification: Bridging the Static/Dynamic Gap - - PowerPoint PPT Presentation
Improving Malware Classification: Bridging the Static/Dynamic Gap Authors: Blake Anderson, Curtis Storlie, Terran Lane Vinit Singh 18 th April 2017 CISC850 Cyber Analytics CISC850 Cyber Analytics INTRODUCTION Why is there a need for
CISC850 Cyber Analytics
CISC850 Cyber Analytics
Binary, Disassembled Binary, Control Flow Graph
Dynamic Instruction Traces (DIT) , Dynamic System Call Traces (DST)
Entropy, Packers, Instructions in file, vertices and edges in CFG
CISC850 Cyber Analytics
CISC850 Cyber Analytics
xi : Features of the file information / transition probability of Markov chain
G: Graph , k : number of nodes of subgraph equal to k DG : Normalized probability vector = fg / # of all graphlets of size k fg = feature vector consisting number of times unique subgraph of size k occurs
Subject to constraint: Thus the Decision function is :