Malfinder: Accelerated Malware Classification System through Filtering on Manycore System

Taegyu Kim, Woomin Hwang, Chulmin Kim, Dong-Jae Shin, Ki-Woong Park, Kyu Ho Park

2015

Abstract

Control flow matching methods have been utilized to detect malware variants. However, as the number of malware variants has soared, it has become harder and harder to detect all malware variants while maintaining high accuracy. Even though many researchers have proposed control flow matching methods, there is still a trade-off between accuracy and performance. To solve this trade-off, we designed Malfinder, a method based on approximate matching, which is accurate but slow. To overcome its low performance, we resolve its performance bottleneck and non-parallelism on three fronts: I-Filter for identical string matching, table division to exclude unnecessary comparisons with some malware and dynamic resource allocation for efficient parallelism. Our performance evaluation shows that the total performance improvement is 280.9 times.

Download


Paper Citation


in Harvard Style

Kim T., Hwang W., Kim C., Shin D., Park K. and Park K. (2015). Malfinder: Accelerated Malware Classification System through Filtering on Manycore System . In Proceedings of the 1st International Conference on Information Systems Security and Privacy - Volume 1: ICISSP, ISBN 978-989-758-081-9, pages 17-26. DOI: 10.5220/0005227500170026

in Bibtex Style

@conference{icissp15,
author={Taegyu Kim and Woomin Hwang and Chulmin Kim and Dong-Jae Shin and Ki-Woong Park and Kyu Ho Park},
title={Malfinder: Accelerated Malware Classification System through Filtering on Manycore System},
booktitle={Proceedings of the 1st International Conference on Information Systems Security and Privacy - Volume 1: ICISSP,},
year={2015},
pages={17-26},
publisher={SciTePress},
organization={INSTICC},
doi={10.5220/0005227500170026},
isbn={978-989-758-081-9},
}


in EndNote Style

TY - CONF
JO - Proceedings of the 1st International Conference on Information Systems Security and Privacy - Volume 1: ICISSP,
TI - Malfinder: Accelerated Malware Classification System through Filtering on Manycore System
SN - 978-989-758-081-9
AU - Kim T.
AU - Hwang W.
AU - Kim C.
AU - Shin D.
AU - Park K.
AU - Park K.
PY - 2015
SP - 17
EP - 26
DO - 10.5220/0005227500170026