A Framework for Collecting and Analysis PE Malware Using Modern Honey Network (MHN)


연구 분야: Safety



학회: 2020 8th International Conference on Cyber and IT Service Management (CITSM)


초록

Nowadays, Windows is an operating system that is very popular among people, especially users who have limited knowledge of computers. But unconsciously, the security threat to the windows operating system is very high. Security threats can be in the form of illegal exploitation of the system. The most common attack is using malware. To determine the characteristics of malware using dynamic analysis techniques and static analysis is very dependent on the availability of malware samples. Honeypot is the most effective malware collection technique. But honeypot cannot determine the type of file format contained in malware. File format information is needed for the purpose of handling malware analysis that is focused on windows-based malware. For this reason, we propose a framework that can collect malware information as well as identify malware PE file type formats. In this study, we collected malware samples using a modern honey network. Next, we performed a feature extraction to determine the PE file format. Then, we classify types of malware using VirusTotal scanning. As the results of this study, we managed to get 1.222 malware samples. Out of 1.222 malware samples, we successfully extracted 945 PE malware. This study can help researchers in other research fields, such as machine learning and deep learning, for malware detection.


Author Profile
Iik Muhamad Malik Matin

School of Electrical Engineering and Informatics Bandung Institute of Technology Bandung Indonesia

Andorra
Author Profile
Budi Rahardjo

School of Electrical Engineering and Informatics Bandung Institute of Technology Bandung Indonesia

Andorra

📄 논문 정보

발행 연도 2020년
인용수 7
출판 국가 Andorra
사이트 IEEE
좋아요 수 0

연관 논문 목록 (549건)