To date, a large number of research papers have been written on the classification of malware, its identification, classification into different families and the distinction between malware and goodware. These works have been based on captured malware samples and have attempted to analyse malware and goodware using various techniques, including techniques from the field of artificial intelligence. For example, neural networks have played a significant role in these classification methods. Some of this work also deals with analysing malware using its visualisation. These works usually convert malware samples capturing the structure of malware into image structures, which are then the object of image processing. In this paper, we propose a very unconventional and novel approach to malware visualisation based on dynamic behaviour analysis, with the idea that the images, which are visually very interesting, are then used to classify malware concerning goodware. Our approach opens an extensive topic for future discussion and provides many new directions for research in malware analysis and classification, as discussed in conclusion. The results of the presented experiments are based on a database of 6 589 997 goodware, 827 853 potentially unwanted applications and 4 174 203 malware samples provided by ESET and selected experimental data (images, generating polynomial formulas and software generating images) are available on GitHub for interested readers. Thus, this paper is not a comprehensive compact study that reports the results obtained from comparative experiments but rather attempts to show a new direction in the field of visualisation with possible applications in malware analysis.
翻译:迄今为止,大量研究论文致力于恶意软件的分类、识别、不同家族划分以及恶意软件与良性软件的区分。这些工作基于捕获的恶意软件样本,尝试运用包括人工智能领域技术在内的多种方法分析恶意软件与良性软件。例如,神经网络在这些分类方法中发挥了重要作用。部分研究还涉及通过可视化技术分析恶意软件:通常将捕获恶意软件结构特征的样本转化为图像结构,进而进行图像处理。本文提出了一种基于动态行为分析的恶意软件可视化非常规新颖方法,其核心思想是利用视觉上极具特色的图像,将恶意软件与良性软件进行分类。该方法为未来讨论开辟了广阔主题,并为恶意软件分析与分类研究提供了诸多新方向(详见结论部分)。实验基于ESET提供的6,589,997个良性软件、827,853个潜在有害应用和4,174,203个恶意软件样本数据库,同时将选定的实验数据(图像、生成多项式公式及生成图像的软件)上传至GitHub供读者参考。因此,本文并非全面紧凑的对比实验研究报告,而是尝试展示可视化领域可应用于恶意软件分析的新方向。