NUST Institutional Repository

Malware Detection Using Static and Dynamic Features of a Portable Executable (PE) File

Show simple item record

dc.contributor.author Saba Awan
dc.date.accessioned 2021-01-18T06:37:23Z
dc.date.available 2021-01-18T06:37:23Z
dc.date.issued 2016
dc.identifier.uri http://10.250.8.41:8080/xmlui/handle/123456789/21263
dc.description Supervisor:Nazar Abbas Saqib en_US
dc.description.abstract Rapid proliferation of malware poses severe threat to the computer security and Internet world today. Malware writers have evolved their techniques with the passage of time. Packing tools are also introduced for polymorphic and metamorphic code obfuscation. Traditionally used signature methods for the malware detection process becomes unreliable to detect these zero day malware attacks. Therefore malware researchers are working to search for the unique patterns and characteristics which remain unchangeable despite of code obfuscation. To address this issue, we propose an effective malware detection method based on the integration of static and dynamic features of an executable. The method firstly gathers static features without executing the file which includes PE Header Information and Printable Strings. After running the binary file in a sandbox environment gathers the dynamic features i.e. API call logs. The integrated feature vector is then analyzed and classified. Machine learning algorithms are used for the classification of data. In this research work, we also compared the performance of four classifiers. The proposed methodology takes advantage of both static and dynamic analysis. We conclude that the experimental results prove that our integrated method achieve higher overall accuracy compared to the standalone static and dynamic methods. en_US
dc.publisher CEME-NUST-National Univeristy of Science and Technology en_US
dc.subject Computer Engineering en_US
dc.title Malware Detection Using Static and Dynamic Features of a Portable Executable (PE) File en_US
dc.type Thesis en_US


Files in this item

This item appears in the following Collection(s)

  • MS [331]

Show simple item record

Search DSpace


Advanced Search

Browse

My Account