Visible to the public NBP-MS: Malware Signature Generation Based on Network Behavior Profiling

TitleNBP-MS: Malware Signature Generation Based on Network Behavior Profiling
Publication TypeConference Paper
Year of Publication2022
AuthorsShi, Zhixin, Wang, Xiangyu, Liu, Pengcheng
Conference Name2022 26th International Conference on Pattern Recognition (ICPR)
KeywordsBehavioral sciences, Computer crime, Malware, Pattern recognition, pubcrawl, Resiliency, Scalability, signature based defense, telecommunication traffic
AbstractWith the proliferation of malware, the detection and classification of malware have been hot topics in the academic and industrial circles of cyber security, and the generation of malware signatures is one of the important research directions. In this paper, we propose NBP-MS, a method of signature generation that is based on network traffic generated by malware. Specifically, we utilize the network traffic generated by malware to perform fine-grained profiling of its network behaviors first, and then cluster all the profiles to generate network behavior signatures to classify malware, providing support for subsequent analysis and defense.
DOI10.1109/ICPR56361.2022.9956412
Citation Keyshi_nbp-ms_2022