Similarity hash based scoring of portable executable files for efficient malware detection in IoT

dc.contributor.authorNamanya, Anitta Patience
dc.contributor.authorAwan, Irfan U.
dc.contributor.authorPagna Disso, Jules
dc.contributor.authorYounas, Muhammad
dc.date.accessioned2023-05-05T17:43:25Z
dc.date.available2023-05-05T17:43:25Z
dc.date.issued2020
dc.description.abstractThe current rise in malicious attacks shows that existing security systems are bypassed by malicious files. Similarity hashing has been adopted for sample triaging in malware analysis and detection. File similarity is used to cluster malware into families such that their common signature can be designed. This paper explores four hash types currently used in malware analysis for portable executable (PE) files. Although each hashing technique produces interesting results, when applied independently, they have high false detection rates. This paper investigates into a central issue of how different hashing techniques can be combined to provide a quantitative malware score and to achieve better detection rates. We design and develop a novel approach for malware scoring based on the hashes results. The proposed approach is evaluated through a number of experiments. Evaluation clearly demonstrates a significant improvement (> 90%) in true detection rates of malware.en_US
dc.identifier.citationNamanya, A. P., Awan, I. U., Disso, J. P., & Younas, M. (2020). Similarity hash based scoring of portable executable files for efficient malware detection in IoT. Future Generation Computer Systems, 110, 824-832. https://doi.org/10.1016/j.future.2019.04.044en_US
dc.identifier.urihttps://doi.org/10.1016/j.future.2019.04.044
dc.identifier.urihttps://nru.uncst.go.ug/handle/123456789/8639
dc.language.isoenen_US
dc.publisherFuture Generation Computer Systemsen_US
dc.subjectMalwareen_US
dc.subjectStatic analysisen_US
dc.subjectDetectionen_US
dc.subjectHashesen_US
dc.subjectInternet of thingsen_US
dc.titleSimilarity hash based scoring of portable executable files for efficient malware detection in IoTen_US
dc.typeArticleen_US
Files
Original bundle
Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
Similarity hash based scoring of portable executable files for efficient.pdf
Size:
2.05 MB
Format:
Adobe Portable Document Format
Description:
Article
License bundle
Now showing 1 - 1 of 1
No Thumbnail Available
Name:
license.txt
Size:
1.71 KB
Format:
Item-specific license agreed upon to submission
Description: