Statistical Analysis for Classification of Malicious Software

This paper proposes a new method of the malicious code classification based on statistical analysis of traces WinAPI calls. We have developed a procedure for programs proximity measurement, taking into account the sequence of WinAPI calls, and the similarity of their arguments. Cluster analysis is u...

Full description

Bibliographic Details
Main Authors: Evgeny Petrovich Tumoyan, Ksenia Vasilevna Tsyganok
Format: Article
Language:English
Published: Moscow Engineering Physics Institute 2014-09-01
Series:Bezopasnostʹ Informacionnyh Tehnologij
Subjects:
Online Access:https://bit.mephi.ru/index.php/bit/article/view/180