I-Filter: Identical Structured Control Flow String filter for accelerated malware variant classification

Taegyu Kim, Woomin Hwang, Ki Woong Park, Kyu Ho Park

Research output: Chapter in Book/Report/Conference proceedingConference contribution

2 Scopus citations

Abstract

As the number of malware variants has grown rapidly, classification speed has become crucial in security issues. While several techniques for malware variant classification have been proposed, they involve a speed-accuracy trade-off. In an attempt to achieve a speedy and accurate malware variant classification, we thoroughly analyze previously proposed methods and identify a critical performance bottleneck in string-to-string matching. This paper presents and evaluates a technique called I-Filter that enhances the performance of the previous approach, approximate matching. I-Filter has the following novel mechanism, the hash-based equivalent procedure matching technique. Our performance evaluation confirms that a performance improvement of on average 1,043 times through I-Filtering.

Original languageEnglish (US)
Title of host publicationProceedings - 2014 International Symposium on Biometrics and Security Technologies, ISBAST 2014
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages225-231
Number of pages7
ISBN (Electronic)9781479964444
DOIs
StatePublished - Jan 16 2015
Event2014 4th International Symposium on Biometrics and Security Technologies, ISBAST 2014 - Kuala Lumpur, Malaysia
Duration: Aug 26 2014Aug 27 2014

Publication series

NameProceedings - 2014 International Symposium on Biometrics and Security Technologies, ISBAST 2014

Conference

Conference2014 4th International Symposium on Biometrics and Security Technologies, ISBAST 2014
Country/TerritoryMalaysia
CityKuala Lumpur
Period8/26/148/27/14

All Science Journal Classification (ASJC) codes

  • Computer Science Applications
  • Biotechnology

Fingerprint

Dive into the research topics of 'I-Filter: Identical Structured Control Flow String filter for accelerated malware variant classification'. Together they form a unique fingerprint.

Cite this