Abstract
Recently, as the rapid development of the Internet enabled easy downloading of diverse files, the number of cases of file download from unreliable paths has been increasing. This situation is advantageous in that accessibility to information is improved while being disadvantageous in that there is no defense against exposure to malware. The present paper proposes a method of judging whether programs are malicious based on Cuckoo Sandbox, which is a dynamic malware analysis system and classify the programs by comparing malware programs collected and classified in advance based on the dynamic API call counts of the programs.
This work was supported by the National Research Foundation of Korea (NRF) grant funded by the Korea government (MSIP) (No. NRF-2016R1A2B1012652, the MSIP(Ministry of Science, ICT and Future Planning, Korea, under the ITRC (Information Technology Research Center) support program (IITP-2016-R2718-16-0035) supervised by the IITP (National IT Industry Promotion Agency), the Basic Science Research Program through the NRF funded by the Ministry of Education (NRF-2015R1C1A1A02037561) and the 2016 Yeungnam University Research Grant.
This is a preview of subscription content,log in via an institution to check access.
Access this chapter
Subscribe and save
- Get 10 units per month
- Download Article/Chapter or eBook
- 1 Unit = 1 Article or 1 Chapter
- Cancel anytime
Buy Now
- Chapter
- JPY 3498
- Price includes VAT (Japan)
- eBook
- JPY 22879
- Price includes VAT (Japan)
- Softcover Book
- JPY 28599
- Price includes VAT (Japan)
- Hardcover Book
- JPY 28599
- Price includes VAT (Japan)
Tax calculation will be finalised at checkout
Purchases are for personal use only
Similar content being viewed by others
References
Han, K.-S., Kim, I.-K., Im, E.-G.: Malware family classification method using API sequential characteristic. J. Secur. Eng.8(2), 319–335 (2011)
Park, N.-Y., Kim, Y.-M., Noh, B.-N.: A behavior based detection for malicious code using obfuscation technique. J. Korea Inst. Inf. Secur. Cryptology, June 2006
Kang, T.-W., Cho, J.I., Chung, M.-H., Moon, J.-S.: Malware detection via hybrid analysis for API calls. J. Korea Inst. Inf. Secur. Cryptology, December 2007
Park, J.-W., Moon, S.-T., Son, G.-W., Kim, I.-K., Han, K.-S., Im, E.-G., Kim, I.-G.: An automatic malware classification system using string list and API. J. Secur. Eng.8(5), 611 (2011)
Cuckoo Sandbox.http://www.cuckoosandbox.com
Author information
Authors and Affiliations
Department of Computer Engineering, Yeungnam University, Gyeongsan, Gyeongbuk, 38541, South Korea
Jihun Kim, Seungwon Lee & Jonghee M. Youn
Department of Multimedia Engineering, Hanbat National University, Daejeon, 34158, South Korea
Haechul Choi
- Jihun Kim
You can also search for this author inPubMed Google Scholar
- Seungwon Lee
You can also search for this author inPubMed Google Scholar
- Jonghee M. Youn
You can also search for this author inPubMed Google Scholar
- Haechul Choi
You can also search for this author inPubMed Google Scholar
Corresponding author
Correspondence toJonghee M. Youn.
Editor information
Editors and Affiliations
Computer Science and Engineering, Seoul National University of Science and Technology, Seoul, Korea (Republic of)
James J. (Jong Hyuk) Park
Department of Computer Science, Georgia State University, Atlanta, Georgia, USA
Yi Pan
Computer Science and Engineering, Gangneung-Wonju National University, Wonju, Korea (Republic of)
Gangman Yi
University Salerno, Fisciano, Italy
Vincenzo Loia
Rights and permissions
Copyright information
© 2017 Springer Nature Singapore Pte Ltd.
About this paper
Cite this paper
Kim, J., Lee, S., Youn, J.M., Choi, H. (2017). A Study of Simple Classification of Malware Based on the Dynamic API Call Counts. In: Park, J., Pan, Y., Yi, G., Loia, V. (eds) Advances in Computer Science and Ubiquitous Computing. UCAWSN CUTE CSA 2016 2016 2016. Lecture Notes in Electrical Engineering, vol 421. Springer, Singapore. https://doi.org/10.1007/978-981-10-3023-9_147
Download citation
Published:
Publisher Name:Springer, Singapore
Print ISBN:978-981-10-3022-2
Online ISBN:978-981-10-3023-9
eBook Packages:EngineeringEngineering (R0)
Share this paper
Anyone you share the following link with will be able to read this content:
Sorry, a shareable link is not currently available for this article.
Provided by the Springer Nature SharedIt content-sharing initiative