ERIC Number: EJ1343201
Record Type: Journal
Publication Date: 2020
Pages: 16
Abstractor: As Provided
ISBN: N/A
ISSN: EISSN-2472-2707
EISSN: N/A
Available Date: N/A
GDOM: Granulometry for the Detection of Obfuscated Malware
Aruta, John A.; Schembari, N. Paul
Journal of Cybersecurity Education, Research and Practice, v2020 n2 Article 2 2020
We describe the results of a master's thesis in malware detection and discuss the connection to the learning goals of the project. As part of the thesis, we studied obfuscation of malware, conversion of files into images, image processing, and machine learning, a process of benefit to both the student and faculty. Malware detection becomes significantly more difficult when the malicious specimen is obfuscated or transformed in an attempt to avoid detection. However, computer files have been shown to exhibit evidence of structure when converted into images, so with image processing filters such as granulometry, it is possible to generate a set of features which will help characterize malicious and non-malicious files. If the structures of file-derived images are resistant to obfuscation, these images may be of valuable use in providing malware signatures. We explore image generated file features and their effectiveness to identify malware when used with various machine learning classifiers.
Descriptors: Computer Software, Computer Security, Identification, Deception, Measurement Techniques, Imagery, Mathematics, Accuracy, Mathematical Concepts
Kennesaw State University. 1000 Chastain Road, Kennesaw, Georgia 30144. Tel: 470-578-3568; e-mail: cybersec@kennesaw.edu; Web site: https://digitalcommons.kennesaw.edu/jcerp/
Publication Type: Journal Articles; Reports - Research
Education Level: N/A
Audience: N/A
Language: English
Sponsor: N/A
Authoring Institution: N/A
Grant or Contract Numbers: N/A
Author Affiliations: N/A