Electronics | 卷:9 |
Platform-Independent Malware Analysis Applicable to Windows and Linux Environments | |
Jin Kwak1  Chanwoong Hwang2  Junho Hwang2  Taejin Lee2  | |
[1] Department of Cyber Security, Ajou University, Suwon 16499, Korea; | |
[2] Department of Information Security, Hoseo University, Asan 31499, Korea; | |
关键词: malware analysis; binary analysis; strings analysis; deep neural network; feature importance; | |
DOI : 10.3390/electronics9050793 | |
来源: DOAJ |
【 摘 要 】
Most cyberattacks use malicious codes, and according to AV-TEST, more than 1 billion malicious codes are expected to emerge in 2020. Although such malicious codes have been widely seen around the PC environment, they have been on the rise recently, focusing on IoT devices such as smartphones, refrigerators, irons, and various sensors. As is known, Linux/embedded environments support various architectures, so it is difficult to identify the architecture in which malware operates when analyzing malware. This paper proposes an AI-based malware analysis technology that is not affected by the operating system or architecture platform. The proposed technology works intuitively. It uses platform-independent binary data rather than features based on the structured format of the executable files. We analyzed the strings from binary data to classify malware. The experimental results achieved 94% accuracy on Windows and Linux datasets. Based on this, we expect the proposed technology to work effectively on other platforms and improve through continuous operation/verification.
【 授权许可】
Unknown