Malicious Portable Executables Scoring Methodology using Evidence Combinational Theory with Fuzzy Hashing.
Malware detection and prevention n systems are bypassed by malicious file in computer systems as malware become more complex and vast in number. With the growing need for high performance secure systems, new, efficient and faster malware detection algorithms are required. This implies that better alternatives present day methods have developed or existing methods need to be optimised with new approaches. Fuzzy hashing is an existing static method that has been adopted for sample triaging in malware analysis and detection to speed up the malware analysis processes. File similarity is used to cluster malware into families whose common signature can then be designed. This work explores some of the different hashing techniques that are used in malware analysis now. Although each hashing technique produces interesting results independently, detection of malicious samples based on these results is misleading. Therefore, this study introduces and investigates how different hashing results can be combined to achieve better detection rates. Two evidence combination theory based methods are applied in this work in order propose a novel way of combining the results achieved from different hashing algorithms. Our results show that the detection rates are improved when evidence combination techniques are applied.
We are delighted once again to announce that Anitta Patience Namanya, the University of Bradford ACM Chapter Secretary has been offered a Scholarship following the acceptance of her poster paper: Malicious PE Static Scoring method using Evidence Combinational Theory with Fuzzy Hashing to attend the ACM-W
Europe Celebration of Women in computing: womENcourage 2016 Conference to be held in Linz, Austria on September 12th and 13th, 2016. This is her second award in less than 12 months, the first being A framework for automated hybrid signature generation for Portable Executable malware detection which was selected as the 2nd top at the ACM-W UK Inspire 2015 Poster Competition held on October 28, 2015 at Imperial College London.
Congratulations Anitta,
University of Bradford ACM Student Chapter is proud of you, best wishes in your research.
Our next seminar presentation is scheduled as follows:
The following are interim events for the Chapter for the 2016/2017 academic session.
ACM-Events-2016-2017The chapter is cosponsoring the 32nd UKPEW and CyberSec Workshop to be held between 8-9th Sept 2016 at the University of Bradford. More details in the flyer below.
32nd-UKPEW-and-CyberSecW-2016-Poster_A3v3