The popularity of dynamic malware analysis has grown significantly, as it enables analysts to observe the behavior of executing samples, thereby enhancing malware detection and classification decisions. With the continuous increase in new malware variants, there is an urgent need for an automated malware analysis engine capable of accurately identifying malware samples. In this paper, we provide a brief overview of malware detection and classification methodologies. Moreover, we introduce a novel framework tailored for the dynamic analysis environment, called the Incremental Malware Detection and Classification Framework (IMDCF). IMDCF offers a comprehensive solution for general-purpose malware detection and classification, achieving an accuracy rate of 96.49% while maintaining a simple architecture.
翻译:动态恶意软件分析的普及程度显著增长,因为它使分析人员能够观察运行样本的行为,从而增强恶意软件检测与分类决策。随着新型恶意软件变种的持续增加,迫切需要一种能够准确识别恶意软件样本的自动化分析引擎。本文简要概述了恶意软件检测与分类方法,并提出了一种专为动态分析环境设计的新型框架——增量式恶意软件检测与分类框架(IMDCF)。该框架为通用恶意软件检测与分类提供了全面解决方案,在保持简洁架构的同时达到了96.49%的准确率。