Profile hidden Markov models and metamorphic virus detection

被引:52
作者
Attaluri, Srilatha [1 ]
McGhee, Scott [1 ]
Stamp, Mark [1 ]
机构
[1] San Jose State Univ, Dept Comp Sci, San Jose, CA 95192 USA
来源
JOURNAL IN COMPUTER VIROLOGY AND HACKING TECHNIQUES | 2009年 / 5卷 / 02期
关键词
D O I
10.1007/s11416-008-0105-1
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Metamorphic computer viruses "mutate" by changing their internal structure and, consequently, different instances of the same virus may not exhibit a common signature. With the advent of construction kits, it is easy to generate metamorphic strains of a given virus. In contrast to standard hidden Markov models (HMMs), profile hidden Markov models (PHMMs) explicitly account for positional information. In principle, this positional information could yield stronger models for virus detection. However, there are many practical difficulties that arise when using PHMMs, as compared to standard HMMs. PHMMs are widely used in bioinformatics. For example, PHMMs are the most effective tool yet developed for finding family related DNA sequences. In this paper, we consider the utility of PHMMs for detecting metamorphic virus variants generated from virus construction kits. PHMMs are generated for each construction kit under consideration and the resulting models are used to score virus and non-virus files. Our results are encouraging, but several problems must be resolved for the technique to be truly practical.
引用
收藏
页码:151 / 169
页数:19
相关论文
共 32 条
[1]  
Attaluri S., 2007, PROFILE HIDDEN MARKO
[2]  
Bilar D., STAT STRUCTURES FING
[3]  
Borello J.-M., 2008, J COMPUTER VIROLOGY
[4]  
BRUSCHI D., 2006, P INT S SEC SOFTW EN
[5]  
Chiueh T.-C., LOOK CURRENT MALWARE
[6]  
Collberg C., TAXONOMY OBFUSCATING
[7]  
Durbin R, 1988, BIOL SEQUENCE ANAL P
[8]   Profile hidden Markov models [J].
Eddy, SR .
BIOINFORMATICS, 1998, 14 (09) :755-763
[9]  
Feng D-F, 1987, J MOL BIOL EVOL, V13, P93
[10]  
Ferrie P., 2004, VIRUS B APR, P4