Abstract
Static malware detection approaches are time-consuming and cannot deal with code obfuscation techniques. Dynamic malware detection approaches, on the other hand, address these two challenges, however, suffer from behavioral ambiguity, such as the system calls obfuscation. In this paper, we introduce Markhor, a dynamic and behavior-based malware detection approach. Markhor uses system call data dependency and system call control dependency sequences to create a weighted list of malicious patterns. The list is then used to determine the malicious processes. Next, the similarity of a file system call sequences to a malicious pattern is extracted based on a fuzzy algorithm and the file nature is determined. The evaluation results reveal the efficiency of Markhor in terms of accuracy (0.982), precision (0.976), and F-measure (0.982).
| Original language | English |
|---|---|
| Pages (from-to) | 81-90 |
| Number of pages | 10 |
| Journal | Journal of Computer Virology and Hacking Techniques |
| Volume | 18 |
| Issue number | 2 |
| DOIs | |
| State | Published - Jun 2022 |
Fingerprint
Dive into the research topics of 'Markhor: malware detection using fuzzy similarity of system call dependency sequences'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver