Back to Search Start Over

Applying NLP techniques to malware detection in a practical environment.

Authors :
Mimura, Mamoru
Ito, Ryo
Source :
International Journal of Information Security. Apr2022, Vol. 21 Issue 2, p279-291. 13p.
Publication Year :
2022

Abstract

Executable files still remain popular to compromise the endpoint computers. These executable files are often obfuscated to avoid anti-virus programs. To examine all suspicious files from the Internet, dynamic analysis requires too much time. Therefore, a fast filtering method is required. With the recent development of natural language processing (NLP) techniques, printable strings became more effective to detect malware. The combination of the printable strings and NLP techniques can be used as a filtering method. In this paper, we apply NLP techniques to malware detection. This paper reveals that printable strings with NLP techniques are effective for detecting malware in a practical environment. Our dataset consists of more than 500,000 samples obtained from multiple sources. Our experimental results demonstrate that our method is effective to not only subspecies of the existing malware, but also new malware. Our method is effective against packed malware and anti-debugging techniques. [ABSTRACT FROM AUTHOR]

Details

Language :
English
ISSN :
16155262
Volume :
21
Issue :
2
Database :
Academic Search Index
Journal :
International Journal of Information Security
Publication Type :
Academic Journal
Accession number :
155888681
Full Text :
https://doi.org/10.1007/s10207-021-00553-8