• Home
  • Search
  • Implementation of Portable Executable File Analysis Framework (PEFAF)
  • Cite Icon9
  • https://doi.org/10.1109/ibcast.2019.8667202Copy DOI Icon

Implementation of Portable Executable File Analysis Framework (PEFAF)

  • Jan 1, 2019
  • M Shahid Yousaf +2 more
Show More
  • Abstract
  • Literature Map
  • References
  • Citations
  • Similar Papers
Abstract

The Portable executable file format is the format of executables, object code and DLL’s (Dynamic Link Library) in Microsoft Windows Operating system. It is the standard of how executable files are organized within file system in Microsoft Windows. The Portable executable file format was designed for Windows NT 3.1 that released in 1993. Many of its features are inherited from COFF (Common object file format) used in Unix Operating systems. It consists of header and sections; headers are rules that tell windows loader how the section should be mapped and loaded into memory. The section are nothing but the data or content. Different sections hold different kind of data for example code section contains executable code while bss (Block Started by Symbol) sections contains uninitialized data. Portable executable file could be used in a way to dent the security of computer, therefore great care should be taken while downloading and running Portable executable files. In our work we develop a static malware analysis tool called ‘Portable Executable File Analysis Framework (PEFAF)’ using data mining techniques. A collection of 8 thousand benign and 7 thousand malicious files were used in this work. We extracted 60 features, analyzed them and found that 34 of them are significant for the detection of malware threats. Based on these 34 indicators our tool classifies input file into malicious or non-malicious.

Similar Papers
  • Single Book

Research on detecting mechanism for Trojan horse based on PE file /

  • Jan 01, 2009
  • Ming Pan
  • PDF
  • Research Article

Software Information Hiding Algorithm Based on Palette Icon of PE File

  • Jan 01, 2022
  • Intelligent Automation & Soft Computing
  • Zuwei Tian +2
  • Conference Article
  • Citations11

On the Design of Supervised Binary Classifiers for Malware Detection Using Portable Executable Files

  • Dec 01, 2019
  • Hrushikesh Shukla +5
  • Research Article

Malware Detection with CNNs on Entropy and Greyscale Images

  • Jan 08, 2026
  • Latin-American Journal of Computing
  • Harry John Darton
  • Research Article
  • Citations41

Wavelet decomposition of software entropy reveals symptoms of malicious code

  • Dec 01, 2016
  • Journal of Innovation in Digital Ecosystems
  • Michael Wojnowicz +3
  • Research Article
  • Citations20

Distinguishing malicious programs based on visualization and hybrid learning algorithms

  • Nov 09, 2021
  • Computer Networks
  • Sanjeev Kumar +1
  • Research Article

BrainLiner: A Platform for Neurophysiological Data Sharing and Manipulation

  • Jan 01, 2011
  • Frontiers in Neuroinformatics
  • Kamitani Yukiyasu
  • Conference Article
  • Citations31

An Opcode Sequences Analysis Method For Unknown Malware Detection

  • Mar 15, 2019
  • Zhi Sun +6
  • Conference Article
  • Citations14

Malware Detection using Attributed CFG Generated by Pre-trained Language Model with Graph Isomorphism Network

  • Jun 01, 2022
  • Yun Gao +3
  • Research Article
  • Citations5

Proper use of common image file formats in handling radiological images

  • Mar 27, 2009
  • La radiologia medica
  • N Faccioli +4
  • PDF
  • Research Article
  • Citations12

Malicious Powershell Detection Using Graph Convolution Network

  • Jul 12, 2021
  • Applied Sciences
  • Sunoh Choi
  • Conference Article
  • Citations62

Malware detection based on opcode frequency

  • May 01, 2016
  • Abhijit Yewale +1
  • Research Article

Malware Detection and Classification using Shapley Additive Explanations Values in Machine Learning

  • Feb 03, 2026
  • International Journal of Computer Network and Information Security
  • Balachandra Chikkoppa +2
  • Research Article
  • Citations4

Executable Code Recognition in Network Flows Using Instruction Transition Probabilities

  • Jul 01, 2008
  • IEICE Transactions on Information and Systems
  • I Kim +6
  • Research Article
  • Citations22

An IRL-based malware adversarial generation method to evade anti-malware engines

  • Nov 19, 2020
  • Computers & Security
  • Xintong Li +1
Cactus Communications logo

Copyright 2026 Cactus Communications. All rights reserved.