NBP-MS: Malware Signature Generation Based on Network Behavior Profiling
Author
Abstract

With the proliferation of malware, the detection and classification of malware have been hot topics in the academic and industrial circles of cyber security, and the generation of malware signatures is one of the important research directions. In this paper, we propose NBP-MS, a method of signature generation that is based on network traffic generated by malware. Specifically, we utilize the network traffic generated by malware to perform fine-grained profiling of its network behaviors first, and then cluster all the profiles to generate network behavior signatures to classify malware, providing support for subsequent analysis and defense.

Year of Publication
2022
Conference Name
2022 26th International Conference on Pattern Recognition (ICPR)
Google Scholar | BibTeX