Dynamic malware analysis has become popular because it allows analysts to observe the behavior of running samples, facilitating improved decisions for malware detection and classification. With the increasing number of new malware, there is a growing need for an automated malware analysis engine that can accurately detect malware samples. In this paper, we briefly introduce the malware detection and classification approaches. Furthermore, we introduce a new malware detection and classification framework that works specifically in the dynamic analysis setting, namely Incremental Malware Detection and Classification Framework, or IMDCF. In this paper, we present a novel framework designed specifically for the dynamic analysis setting, named the Incremental Malware Detection and Classification Framework (IMDCF). IMDCF provides a end-to-end solution for general-purpose malware detection and classification with 96.49\% accuracy and simple architecture.
翻译:动态恶意软件分析因其能使分析人员观察运行样本的行为,从而促进恶意软件检测与分类决策的改进而日益普及。随着新型恶意软件数量的不断增长,对能够精确检测恶意软件样本的自动化分析引擎的需求也日益迫切。本文简要介绍了恶意软件检测与分类方法。在此基础上,我们提出了一种专门适用于动态分析场景的新型恶意软件检测与分类框架,即增量式恶意软件检测与分类框架(IMDCF)。该框架提供了一个面向通用恶意软件检测与分类的端到端解决方案,其准确率达96.49%,且架构简洁。