• Complex
  • Title
  • Keyword
  • Abstract
  • Scholars
  • Journal
  • ISSN
  • Conference
成果搜索

author:

Ye, Y. (Ye, Y..) [1] | Wang, D. (Wang, D..) [2] | Li, T. (Li, T..) [3] | Ye, D. (Ye, D..) [4] | Jiang, Q. (Jiang, Q..) [5]

Indexed by:

Scopus

Abstract:

The proliferation of malware has presented a serious threat to the security of computer systems. Traditional signature-based anti-virus systems fail to detect polymorphic/metamorphic and new, previously unseen malicious executables. Data mining methods such as Naive Bayes and Decision Tree have been studied on small collections of executables. In this paper, resting on the analysis of Windows APIs called by PE files, we develop the Intelligent Malware Detection System (IMDS) using Objective-Oriented Association (OOA) mining based classification. IMDS is an integrated system consisting of three major modules: PE parser, OOA rule generator, and rule based classifier. An OOA_Fast_FP-Growth algorithm is adapted to efficiently generate OOA rules for classification. A comprehensive experimental study on a large collection of PE files obtained from the anti-virus laboratory of KingSoft Corporation is performed to compare various malware detection approaches. Promising experimental results demonstrate that the accuracy and efficiency of our IMDS system outperform popular anti-virus software such as Norton AntiVirus and McAfee VirusScan, as well as previous data mining based detection systems which employed Naive Bayes, Support Vector Machine (SVM) and Decision Tree techniques. Our system has already been incorporated into the scanning tool of KingSoft's Anti-Virus software. © 2008 Springer-Verlag France.

Keyword:

Community:

  • [ 1 ] [Ye, Y.]Department of Computer Science, Xiamen University, Xiamen, China
  • [ 2 ] [Wang, D.]School of Computer Science, Florida International University, Miami, FL, United States
  • [ 3 ] [Li, T.]School of Computer Science, Florida International University, Miami, FL, United States
  • [ 4 ] [Ye, D.]College of Maths and Computer Science, Fuzhou University, Fuzhou, China
  • [ 5 ] [Jiang, Q.]Software School, Xiamen University, Xiamen, China

Reprint 's Address:

  • [Li, T.]School of Computer Science, Florida International University, Miami, FL, United States

Show more details

Related Keywords:

Related Article:

Source :

Journal in Computer Virology

ISSN: 1772-9890

Year: 2008

Issue: 4

Volume: 4

Page: 323-334

Cited Count:

WoS CC Cited Count:

SCOPUS Cited Count: 147

ESI Highly Cited Papers on the List: 0 Unfold All

WanFang Cited Count:

Chinese Cited Count:

30 Days PV: 1

Affiliated Colleges:

Online/Total:166/10041275
Address:FZU Library(No.2 Xuyuan Road, Fuzhou, Fujian, PRC Post Code:350116) Contact Us:0591-22865326
Copyright:FZU Library Technical Support:Beijing Aegean Software Co., Ltd. 闽ICP备05005463号-1