Publication: Complexity Reduction on API Call Sequence Alignment Using Unique API Word Sequence
dc.contributor.author | Thotsaphon Tungjitviboonkun | en_US |
dc.contributor.author | Vasin Suttichaya | en_US |
dc.contributor.other | Mahidol University | en_US |
dc.date.accessioned | 2019-08-23T10:55:31Z | |
dc.date.available | 2019-08-23T10:55:31Z | |
dc.date.issued | 2018-08-21 | en_US |
dc.description.abstract | © 2017 IEEE. API call analysis is well-known method for classifing malware based on their behaviors. An analysis based on sequence alignment of API call usually produces the high accuracy result. However, the method suffers from time consuming. Thus, researchers make trade-off between time and accuracy by neglecting API call arguments and/or grouping API calls into character categories. We suggest an approach to preserve API call arguments while reducing the alignment overhead by using longest common unique API word sequence as split points. The proposed method produces high matching sequences while API call arguments are preserved and time complexity is reduced. Moreover, we apply this approach to produce malware subfamily signature, the similar API calls that extracted from aligned sequences. Malware subfamily signatures can be used for detecting malware samples of their family with high accuracy. | en_US |
dc.identifier.citation | ICSEC 2017 - 21st International Computer Science and Engineering Conference 2017, Proceeding. (2018), 15-18 | en_US |
dc.identifier.doi | 10.1109/ICSEC.2017.8443930 | en_US |
dc.identifier.other | 2-s2.0-85053464205 | en_US |
dc.identifier.uri | https://repository.li.mahidol.ac.th/handle/20.500.14594/45593 | |
dc.rights | Mahidol University | en_US |
dc.rights.holder | SCOPUS | en_US |
dc.source.uri | https://www.scopus.com/inward/record.uri?partnerID=HzOxMe3b&scp=85053464205&origin=inward | en_US |
dc.subject | Computer Science | en_US |
dc.title | Complexity Reduction on API Call Sequence Alignment Using Unique API Word Sequence | en_US |
dc.type | Conference Paper | en_US |
dspace.entity.type | Publication | |
mu.datasource.scopus | https://www.scopus.com/inward/record.uri?partnerID=HzOxMe3b&scp=85053464205&origin=inward | en_US |