Generating Rule-based Signatures for Detecting Polymorphic Variants Using Data Mining and Sequence Alignment Approaches

Date
2018-10-19
Authors
Naidu, V
Whalley, J
Narayanan, A
Supervisor
Item type
Journal Article
Degree name
Journal Title
Journal ISSN
Volume Title
Publisher
Scientific Research Publishing
Abstract

Antiviral software systems (AVSs) have problems in identifying polymorphic variants of viruses without explicit signatures for such variants. Alignment- based techniques from bioinformatics may provide a novel way to generate signatures from consensuses found in polymorphic variant code. We demonstrate how multiple sequence alignment supplemented with gap penalties leads to viral code signatures that generalize successfully to previously known polymorphic variants of JS. Cassandra virus and previously unknown polymorphic variants of W32.CTX/W32.Cholera and W32.Kitti viruses. The implications are that future smart AVSs may be able to generate effective signatures automatically from actual viral code by varying gap penalties to cover for both known and unknown polymorphic variants.

Description
Keywords
Polymorphic Malware Variants; Gap Penalties; Syntactic Approach; Pairwise Sequence Alignment; Multiple Sequence Alignment; Automatic Signature Generation; Smith-Waterman Algorithm; JS. Cassandra Virus; W32.CTX/W32.Cholera Virus; W32.Kitti Virus
Source
Journal of Information Security, 8, 296-327. https://doi.org/10.4236/jis.2017.84020
Rights statement
Copyright © 2017 by authors and Scientific Research Publishing Inc.This work is licensed under the Creative Commons Attribution International License (CC BY 4.0).http://creativecommons.org/licenses/by/4.0/