MyJournals Home  

RSS FeedsEntropy, Vol. 21, Pages 513: Mimicking Anti-Viruses with Machine Learning and Entropy Profiles (Entropy)

 
 

21 may 2019 16:01:20

 
Entropy, Vol. 21, Pages 513: Mimicking Anti-Viruses with Machine Learning and Entropy Profiles (Entropy)
 


The quality of anti-virus software relies on simple patterns extracted from binary files. Although these patterns have proven to work on detecting the specifics of software, they are extremely sensitive to concealment strategies, such as polymorphism or metamorphism. These limitations also make anti-virus software predictable, creating a security breach. Any black hat with enough information about the anti-virus behaviour can make its own copy of the software, without any access to the original implementation or database. In this work, we show how this is indeed possible by combining entropy patterns with classification algorithms. Our results, applied to 57 different anti-virus engines, show that we can mimic their behaviour with an accuracy close to 98% in the best case and 75% in the worst, applied on Windows’ disk resident malware.


 
104 viewsCategory: Informatics, Physics
 
Entropy, Vol. 21, Pages 510: The Exponentiated Lindley Geometric Distribution with Applications (Entropy)
Entropy, Vol. 21, Pages 514: Entropy Generation of Forced Convection during Melting of Ice Slurry (Entropy)
 
 
blog comments powered by Disqus


MyJournals.org
The latest issues of all your favorite science journals on one page

Username:
Password:

Register | Retrieve

Search:

Physics


Copyright © 2008 - 2024 Indigonet Services B.V.. Contact: Tim Hulsen. Read here our privacy notice.
Other websites of Indigonet Services B.V.: Nieuws Vacatures News Tweets Nachrichten