JOURNAL ARTICLE

A Method for Detecting Unknown Malicious Executables

Abstract

We present a method for detecting new malicious executables, which comprise the following steps: (a) in an offline training phase, finding a set of (not necessary consecutive) system call sequences that are characteristic only to malicious files, when such malicious files are executed, and storing said sequences in a database; (b) in a real time detection phase, for each running executable, continuously monitoring its issued system calls and comparing with the stored sequences of system calls within the database to determine whether there exists a match between a portion of the sequence of the run-time system calls and one or more of the database sequences, and when such a match is found, declaring said executable as malicious. We have evaluated our method and the preliminary results are promising and justify the use of system calls sequences for the purpose of detection of new malicious executables.

Keywords:
Executable Computer science System call Set (abstract data type) Sequence (biology) Malware Operating system Database Data mining Programming language

Metrics

5
Cited By
0.62
FWCI (Field Weighted Citation Impact)
25
Refs
0.66
Citation Normalized Percentile
Is in top 1%
Is in top 10%

Citation History

Topics

Advanced Malware Detection Techniques
Physical Sciences →  Computer Science →  Signal Processing
Network Security and Intrusion Detection
Physical Sciences →  Computer Science →  Computer Networks and Communications
Software Testing and Debugging Techniques
Physical Sciences →  Computer Science →  Software

Related Documents

BOOK-CHAPTER

Method for Detecting Unknown Malicious Executables

B.A. RozenbergEhud GudesYuval EloviciYuval Fledel

Lecture notes in computer science Year: 2009 Pages: 376-377
JOURNAL ARTICLE

NewApproach for Detecting Unknown Malicious Executables

B.A. RozenbergEhud GudesYuval EloviciYuval Fledel

Journal:   Journal of Forensic Research Year: 2010 Vol: 01 (03)
BOOK-CHAPTER

Data Mining for Detecting Malicious Executables

Auerbach Publications eBooks Year: 2011 Pages: 109-110
BOOK-CHAPTER

Malicious Executables

Auerbach Publications eBooks Year: 2011 Pages: 111-118
© 2026 ScienceGate Book Chapters — All rights reserved.