Sliding window and control flow weight for metamorphic malware detection

dc.contributor.authorAlam, Shahid
dc.contributor.authorSoğukpınar, İbrahim
dc.contributor.authorTraore, Issa
dc.contributor.authorHorspool, R. Nigel
dc.date.accessioned2025-10-29T11:31:05Z
dc.date.issued2015
dc.departmentFakülteler, Mühendislik Fakültesi, Bilgisayar Mühendisliği Bölümü
dc.description.abstractThe latest stealth techniques, such as metamorphism, allow malware to evade detection by today's signature-based anti-malware programs. Current techniques for detecting malware are compute intensive and unsuitable for real-time detection. Techniques based on opcode patterns have the potential to be used for real-time malware detection, but have the following issues: (1) The frequencies of opcodes can change by using different compilers, compiler optimizations and operating systems. (2) Obfuscations introduced by polymorphic and metamorphic malware can change the opcode distributions. (3) Selecting too many features (patterns) results in a high detection rate but also increases the runtime and vice versa. In this paper we present a novel technique named SWOD-CFWeight (Sliding Window of Difference and Control Flow Weight) that helps mitigate these effects and provides a solution to these problems. The SWOD size can be changed; this property gives anti-malware tool developers the ability to select appropriate parameters to further optimize malware detection. The CFWeight feature captures control flow information to an extent that helps detect metamorphic malware in real-time. Experimental evaluation of the proposed scheme using an existing dataset yields a malware detection rate of 99.08% and a false positive rate of 0.93%.
dc.identifier.doi10.1007/s11416-014-0222-y
dc.identifier.endpage88
dc.identifier.issn2263-8733
dc.identifier.issue2
dc.identifier.orcid0000-0002-0408-0277
dc.identifier.orcid0000-0002-4080-8042
dc.identifier.scopus2-s2.0-84941216592
dc.identifier.scopusqualityQ2
dc.identifier.startpage75
dc.identifier.urihttps://doi.org/10.1007/s11416-014-0222-y
dc.identifier.urihttps://hdl.handle.net/20.500.14854/11861
dc.identifier.volume11
dc.identifier.wosWOS:000355688200002
dc.identifier.wosqualityN/A
dc.indekslendigikaynakWeb of Science
dc.indekslendigikaynakScopus
dc.language.isoen
dc.publisherSpringer France
dc.relation.ispartofJournal of Computer Virology and Hacking Techniques
dc.relation.publicationcategoryMakale - Uluslararası Hakemli Dergi - Kurum Öğretim Elemanı
dc.rightsinfo:eu-repo/semantics/closedAccess
dc.snmzKA_WOS_20251020
dc.subjectDistance
dc.titleSliding window and control flow weight for metamorphic malware detection
dc.typeArticle

Dosyalar