Malware detection approach based on the swarm-based behavioural analysis over API calling sequence

Eslam Amer, Adham Samir, Hazem Mostafa, Amer Mohamed, Mohamed Amin

Research output: Chapter in Book/Report/Conference proceedingConference contribution

Abstract

The rapidly increasing malware threats must be coped with new effective malware detection methodologies. Current malware threats are not limited to daily personal transactions but dowelled deeply within large enterprises and organizations. This paper introduces a new methodology for detecting and discriminating malicious versus normal applications. In this paper, we employed Ant-colony optimization to generate two behavioural graphs that characterize the difference in the execution behavior between malware and normal applications. Our proposed approach relied on the API call sequence generated when an application is executed. We used the API calls as one of the most widely used malware dynamic analysis features. Our proposed method showed distinctive behavioral differences between malicious and non-malicious applications. Our experimental results showed a comparative performance compared to other machine learning methods. Therefore, we can employ our method as an efficient technique in capturing malicious applications.

Original languageEnglish
Title of host publicationMIUCC 2022 - 2nd International Mobile, Intelligent, and Ubiquitous Computing Conference
EditorsAyman Bahaa-Eldin, Ashraf AbdelRaouf, Nada Shorim, Samira Refaat, Shereen Essam Elbohy
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages27-32
Number of pages6
ISBN (Electronic)9781665466776
ISBN (Print)9781665466783
DOIs
Publication statusPublished - 1 Jun 2022
Event2nd International Mobile, Intelligent, and Ubiquitous Computing Conference, MIUCC 2022 - Cairo, Egypt
Duration: 8 May 20229 May 2022

Conference

Conference2nd International Mobile, Intelligent, and Ubiquitous Computing Conference, MIUCC 2022
Country/TerritoryEgypt
CityCairo
Period8/05/229/05/22

Keywords

  • Ant Colony
  • API calling sequence
  • Dynamic Analysis
  • Word Embedding

Fingerprint

Dive into the research topics of 'Malware detection approach based on the swarm-based behavioural analysis over API calling sequence'. Together they form a unique fingerprint.

Cite this