• Home
  • Search
  • Efficient Dynamic Malware Analysis Based on Network Behavior Using Deep Learning
  • Cite Icon92
  • https://doi.org/10.1109/glocom.2016.7841778Copy DOI Icon

Efficient Dynamic Malware Analysis Based on Network Behavior Using Deep Learning

  • Dec 1, 2016
  • Toshiki Shibahara +4 more
Show More
  • Abstract
  • Literature Map
  • References
  • Citations
  • Similar Papers
Abstract

Malware authors or attackers always try to evade detection methods to accomplish their mission. Such detection methods are broadly divided into three types: static feature, host-behavior, and network-behavior based. Static feature-based methods are evaded using packing techniques. Host- behavior-based methods also can be evaded using some code injection methods, such as API hook and dynamic link library hook. This arms race regarding static feature-based and host-behavior- based methods increases the importance of network-behavior-based methods. The necessity of communication between infected hosts and attackers makes it difficult to evade network-behavior- based methods. The effectiveness of such methods depends on how we collect a variety of communications by using malware samples. However, analyzing all new malware samples for a long period is infeasible. Therefore, we propose a method for determining whether dynamic analysis should be suspended based on network behavior to collect malware communications efficiently and exhaustively. The key idea behind our proposed method is focused on two characteristics of malware communication: the change in the communication purpose and the common latent function. These characteristics of malware communications resemble those of natural language from the viewpoint of data structure, and sophisticated analysis methods have been proposed in the field of natural language processing. For this reason, we applied the recursive neural network, which has recently exhibited high classification performance, to our proposed method. In the evaluation with 29,562 malware samples, our proposed method reduced 67.1% of analysis time while keeping the coverage of collected URLs to 97.9% of the method that continues full analyses.

Similar Papers
  • Research Article
  • Citations4

Efficient Dynamic Malware Analysis for Collecting HTTP Requests using Deep Learning

  • Apr 01, 2019
  • IEICE Transactions on Information and Systems
  • Toshiki Shibahara +4
  • PDF
  • Research Article
  • Citations67

Malware Classification Using Probability Scoring and Machine Learning

  • Jan 01, 2019
  • IEEE Access
  • Di Xue +4
  • Book Chapter

Concluding Remarks

  • Aug 14, 2012
  • Heng Yin +1
  • Conference Article
  • Citations111

Identifying Dormant Functionality in Malware Programs

  • Jan 01, 2010
  • Paolo Milani Comparetti +5
  • Conference Article
  • Citations4

ByteFreq: Malware clustering using byte frequency

  • Sep 01, 2016
  • Nirmal Singh +1
  • Conference Article
  • Citations19

Malware Analysis of Imaged Binary Samples by Convolutional Neural Network with Attention Mechanism

  • Nov 03, 2017
  • Hiromu Yakura +4
  • Research Article
  • Citations20

Distinguishing malicious programs based on visualization and hybrid learning algorithms

  • Nov 09, 2021
  • Computer Networks
  • Sanjeev Kumar +1
  • Research Article
  • Citations62

Ensemble Clustering for Internet Security Applications

  • Nov 01, 2012
  • IEEE Transactions on Systems, Man, and Cybernetics, Part C (Applications and Reviews)
  • Weiwei Zhuang +3
  • Conference Article
  • Citations17

Automatic Text Summarization of Legal Cases: A Hybrid Approach

  • Aug 17, 2019
  • Varun Pandya
  • Conference Article
  • Citations41

DRACO

  • Sep 08, 2015
  • Shweta Bhandari +5
  • Research Article
  • Citations22

Malware Detection Using LightGBM With a Custom Logistic Loss Function

  • Jan 01, 2022
  • IEEE Access
  • Yun Gao +3
  • Conference Article
  • Citations14

IoT Botnet detection based on the integration of static and dynamic vector features

  • Jan 13, 2021
  • Quoc-Dung Ngo +3
  • Research Article
  • Citations28

Cross-Modal Multistep Fusion Network With Co-Attention for Visual Question Answering

  • Jan 01, 2018
  • IEEE Access
  • Mingrui Lao +3
  • Book Chapter

Malware Analysis With Machine Learning

  • Sep 26, 2023
  • Ravi Singh +1
  • Book Chapter
  • Citations2

Instruction Cognitive One-Shot Malware Outbreak Detection

  • Jan 01, 2019
  • Sean Park +3
Cactus Communications logo

Copyright 2026 Cactus Communications. All rights reserved.