
doi: 10.13016/m25d3g
Metamorphic malware tend to change its code structure, every time it infects a new host machine. This makes classification and subsequent detection of the malware very difficult. Unlike other viruses, metamorphic malware uses code obfuscation techniques on the body of the malware and that way the malware structure does not exhibit a common signature. With the advent of advanced malware construction kits, it is easy to generate numerous metamorphic variations of the same malware. In spite of meticulously changing the code structure for every infection, the core functionality of the malware remains unchanged. We present methods to classify and detect metamorphic malware by doing a static analysis of the opcode sequences in the malware specimens. The opcodes (words) from the assembly files of specimens are analyzed to construct word distributions and learn topic distributions, using Latent Dirichlet Allocation (LDA), for each malware specimen. Using the topic and word distributions as features, we build classifiers to predict the family of each specimen using the RUSBoost and multi-class AdaBoost algorithms. We experimentally evaluate our methods using a real dataset of 400 malware specimens from four families and 25 benign specimens. We find that classification into malware families using the word distribution features is more accurate and robust than the classification using the LDA-learned topic distribution features. We also find that the classification accuracy is stable under simple substitutions of opcodes with short equivalent opcode sequences. Topic distribution features provide comparable classification performance upon significantly increasing the computational cost (number of iterations) of LDA. Moreover, using a surrogate data testing approach we find that the association between word/topic distributions and malware families is significant.
Decision trees, Latent Dirichlet Allocation, Metamorphic Malware, Topic modelling, Boosting, Surrogate data testing
Decision trees, Latent Dirichlet Allocation, Metamorphic Malware, Topic modelling, Boosting, Surrogate data testing
| selected citations These citations are derived from selected sources. This is an alternative to the "Influence" indicator, which also reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically). | 0 | |
| popularity This indicator reflects the "current" impact/attention (the "hype") of an article in the research community at large, based on the underlying citation network. | Average | |
| influence This indicator reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically). | Average | |
| impulse This indicator reflects the initial momentum of an article directly after its publication, based on the underlying citation network. | Average |
