• 中国计算机学会会刊
  • 中国科技核心期刊
  • 中文核心期刊

J4 ›› 2014, Vol. 36 ›› Issue (03): 481-486.

• 论文 • Previous Articles     Next Articles

Similarity analysis of malware’s function-call graphs                 

LIU Xing,TANG Yong   

  1. (College of Computer,National University of Defense Technology,Changsha 410073,China)
  • Received:2012-12-03 Revised:2013-02-17 Online:2014-03-25 Published:2014-03-25

Abstract:

The similarity analysis of malware is an important part of the current automatic analysis of malware. The paper proposes a new method of similarity analysis of malware based on functioncall graphs. This method uses the similarity distance of malware’s function-call graphs (called SDMFG) to measure the similarity of two malwares’ function-call graphs, and then analyzes the similarity of the two malwares. This method improves the accuracy of similarity analysis of malware, providing a strong support for analysis of the homology and evolution characteristics of malware and malware detection and prevention.Key words:

Key words: malware;function-call graph;SDMFG;instruction sequence;max-weight matching