DSpace Repository

Detection of malicious portable executable files using static features

Show simple item record

dc.contributor.author Abrar Ahmed, 01-247172-031
dc.date.accessioned 2020-12-25T00:32:43Z
dc.date.available 2020-12-25T00:32:43Z
dc.date.issued 2019
dc.identifier.uri http://hdl.handle.net/123456789/10587
dc.description Supervised by Dr. Sumaira Kausar en_US
dc.description.abstract Signature-based pattern matching is one of the most popular techniques used for detection of malwares. Malware signatures are stored in malware database which are used for pattern matching detection. However, similarity is calculated between the input data and the stored signature. Many problems can be faced undoubtedly (i.e calculation over-head and storage capacity problem). The detection process of malicious code can be bypassed through code obfuscation technique. So, use of machine learning comes into play for the detection of benign and malicious PE files. However, the previous techniques were limited for detecting the malware families. In our research, different PE file header fields are used as features which are obtained through parsing of PE files. Most significant features were selected after the process of feature engineering. Unsupervised machine learning techniques are used for the detection of malicious PE files. Partition based and density based clustering algorithms are applied over sample dataset. K-Means clustering and DBSCAN clustering algorithms are evaluated. Partition based clustering i.e k-Means out performs for classifying malicious and benign PE files. en_US
dc.language.iso en en_US
dc.publisher Bahria University Islamabad Campus en_US
dc.relation.ispartofseries MS (IS);T-8862
dc.subject Information Security en_US
dc.title Detection of malicious portable executable files using static features en_US
dc.type Thesis en_US


Files in this item

This item appears in the following Collection(s)

Show simple item record

Search DSpace


Advanced Search

Browse

My Account