Malware Identification by Instruction Level Code Analysis

CSEF · 2011 Mathematics & Software

Overview

Objectives/Goals In this project, we created models of malware and goodware (normal software) using the composing assembly instructions of executables, and then we measured the effectiveness of these models at identifying malicious code. The objective is to determine the efficacy of this new method at distinguishing the two types of software. Methods/Materials 53514 malware programs were obtained from the Anubis research group, and 4115 goodware were collected from a Virtual Machine created for this project. We used the Naive Bayes, Kmeans, and Support Vector Machine algorithms to create models of malware and goodware, and then we determined the effectiveness of these classifiers at differentiating malicious code from normal code. Results The classifiers were effective at distinguishing malware from goodware. Conclusions/Discussion We successfully created models of malware and goodware that differentiate the two types of software using program assembly instructions. The results indicate that this method could likely be implemented in modern antivirus solutions.

Summary statement

This project investigates the effectiveness of models that use program assembly instructions to differentiate malware from normal software.

Help received

My teacher Dr. Durkee read my papers; My mentor Joshua Kroll taught me about machine learning and obtained the malware set.

Competition history

  • CSEF 2011 Mathematics & Software · Entry S1403

Resources

Related projects

Closest projects by meaning, across every fair and year in the corpus.

Browse more like this

Source: California Science & Engineering Fair public projects

Save projects to your library

Sign in with Google to keep track of projects you find interesting, organized into folders. An account also raises your daily allowance for “Has this been done?”, and lets you create a key for the MCP server with a much higher limit than anonymous use. Browsing stays public.

Continue with Google