Noble Feature Extraction of Malware from Contents of File

International Journal of Computer Trends and Technology (IJCTT)          
© 2017 by IJCTT Journal
Volume-48 Number-4
Year of Publication : 2017
Authors : Hemant J. Chaudhari, Prof. M. S. Mahindrakar


Abstract -
Malware family identification is a critical process involving extraction of distinctive property from a set of malware samples. Now a day several malware authors use various techniques to prevent the identification of unique property of their programs, such as, encryption and obfuscation. In this paper, we present features extraction of malware from contents of the file. First of all we scanning sample dataset or executable file through the virus total online tool[4] then disassemble given file by using IDA pro tool[1]; Convert given file into N-gram sequential pattern by using KfNgram tool[2]; Measurement of used symbols, sections, metadata and finally calculate the entropy. Our goal in this research is to introduce a noble set of features to understood malware features.

Feature Extraction of Malware, N-gram, Sequential pattern, Malware features, Set of attributes, Metadata, Malicious Symbols, Sections, Entropy.