Effective, Efficient, and Robust Packing Detection and Classification - Archive ouverte HAL Access content directly
Journal Articles Computers and Security Year : 2018

Effective, Efficient, and Robust Packing Detection and Classification

(1) , (2) , (2) , (3, 4) , (2) , (2)
1
2
3
4

Abstract

Packing is a widespread tool to prevent static malware detection and analysis. Detecting and classifying the packer used by a given malware sample is fundamental to being able to unpack and study the malware, whether manually or automatically. Existing literature on packing detection and classification has focused on effectiveness, but does not consider the efficiency required to be part of a practical malware-analysis workflow. This paper studies how to train packing detection and classification algorithms based on machine learning to be both highly effective and efficient. Initially, we create ground truths by labeling more than 280,000 samples with three different techniques. Then we perform feature selection considering the contribution and computation cost of features. Then we iterate over more than 1,500 combinations of features, scenarios, and algorithms to determine which algorithms are the most effective and efficient, finding that a reduction of 1-2% effectiveness can increase efficiency by 17-44 times. Then, we test how the best algorithms perform against malware collected after the training data to assess them against new packing techniques and versions, finding a large impact of the ground truth used on algorithm robustness. Finally, we perform an economic analysis and find simple algorithms with small feature sets to be more economical than complex algorithms with large feature sets based on uptime/training time ratio.
Fichier principal
Vignette du fichier
main.pdf (885.13 Ko) Télécharger le fichier
Origin : Files produced by the author(s)
Loading...

Dates and versions

hal-01967597 , version 1 (31-12-2018)

Identifiers

  • HAL Id : hal-01967597 , version 1

Cite

Fabrizio Biondi, Michael A Enescu, Thomas Given-Wilson, Axel Legay, Lamine Noureddine, et al.. Effective, Efficient, and Robust Packing Detection and Classification. Computers and Security, In press, pp.1-15. ⟨hal-01967597⟩
264 View
1064 Download

Share

Gmail Facebook Twitter LinkedIn More