Archive - Central European Conference on Information and Intelligent Systems, CECIIS - 2010

Font Size: 
A multiple layered approach to malware identification and classification problem
Tonimir Kišasondi, Domagoj Klasić, Željko Hutinski

Last modified: 2010-08-16

Abstract


The increasing threat of malware is a constant problem for information system security. Current detection methods are showing lack in sufficience and are bulky, with a slow response to high traffic needs and for new samples. In this work we will present a method for in-depth malware identification and classification. We will show a concept of a multi layered approach where we can detect and classify malware mixed with legit data samples based on speed or precision trade-offs. We will employ a classification and risk based method with various detection criteria that can identify various hazardous aspects of various malware instances. The classifiers will be organized in layers which will help us in building various high speed or high precision detectors based on the protection needs and requirements.

Full Text: PDF