Ajou University repository

Fast k-NN based Malware Analysis in a Massive Malware Environmentoa mark
Citations

SCOPUS

3

Citation Export

DC Field Value Language
dc.contributor.authorHwang, Jun ho-
dc.contributor.authorKwak, Jin-
dc.contributor.authorLee, Tae jin-
dc.date.issued2019-12-31-
dc.identifier.urihttps://dspace.ajou.ac.kr/dev/handle/2018.oak/31087-
dc.description.abstractIt is a challenge for the current security industry to respond to a large number of malicious codes distributed indiscriminately as well as intelligent APT attacks. As a result, studies using machine learning algorithms are being conducted as proactive prevention rather than post processing. The k-NN algorithm is widely used because it is intuitive and suitable for handling malicious code as unstructured data. In addition, in the malicious code analysis domain, the k-NN algorithm is easy to classify malicious codes based on previously analyzed malicious codes. For example, it is possible to classify malicious code families or analyze malicious code variants through similarity analysis with existing malicious codes. However, the main disadvantage of the k-NN algorithm is that the search time increases as the learning data increases. We propose a fast k-NN algorithm which improves the computation speed problem while taking the value of the k-NN algorithm. In the test environment, the k-NN algorithm was able to perform with only the comparison of the average of similarity of 19.71 times for 6.25 million malicious codes. Considering the way the algorithm works, Fast k-NN algorithm can also be used to search all data that can be vectorized as well as malware and SSDEEP. In the future, it is expected that if the k-NN approach is needed, and the central node can be effectively selected for clustering of large amount of data in various environments, it will be possible to design a sophisticated machine learning based system.-
dc.description.sponsorshipThis work was supported by the National Research Foundation of Korea(NRF) grant funded by the Korea government(MSIT) (No. NRF-2018R1C1B5029849 ) and by the National Research Foundation of Korea(NRF) grant funded by the Korea government(MSIT)(No. NRF-2017R1E1A1A01075110).-
dc.language.isoeng-
dc.publisherKorean Society for Internet Information-
dc.subject.meshClustering-
dc.subject.meshComputation speed-
dc.subject.meshK-nearest neighbors-
dc.subject.meshMalicious-code analysis-
dc.subject.meshSecurity industry-
dc.subject.meshSimilarity analysis-
dc.subject.meshSophisticated machines-
dc.subject.meshUnstructured data-
dc.titleFast k-NN based Malware Analysis in a Massive Malware Environment-
dc.typeArticle-
dc.citation.endPage6158-
dc.citation.startPage6145-
dc.citation.titleKSII Transactions on Internet and Information Systems-
dc.citation.volume13-
dc.identifier.bibliographicCitationKSII Transactions on Internet and Information Systems, Vol.13, pp.6145-6158-
dc.identifier.doi10.3837/tiis.2019.12.019-
dc.identifier.scopusid2-s2.0-85077491005-
dc.identifier.urlhttp://itiis.org/digital-library/23099-
dc.subject.keywordClustering-
dc.subject.keywordK-Nearest Neighbor-
dc.subject.keywordMalware-
dc.description.isoatrue-
dc.subject.subareaInformation Systems-
dc.subject.subareaComputer Networks and Communications-
Show simple item record

Items in DSpace are protected by copyright, with all rights reserved, unless otherwise indicated.

Related Researcher

KWAK, JIN Image
KWAK, JIN곽진
Department of Cyber Security
Read More

Total Views & Downloads

File Download

  • There are no files associated with this item.