In this study we have presented a novel feature representation for malicious programs that can be used for malware classification. We have shown how to construct the features in a bottom-up approach, and analyzed the overlap of malicious and benign programs in terms of their components. We have shown that our method of analysis offers an increase in feature resolution that is descriptive of data movement in comparison to tf-idf features.
翻译:在这项研究中,我们展示了可用于恶意软件分类的恶意程序的新特征说明。我们已经展示了如何以自下而上的方法构建这些特征,并分析了恶意和良性程序各组成部分的重叠。我们已经显示,我们的分析方法增加了特征分辨率,即描述数据相对于tf-IDf特性的移动。