Exploring the Effects of Gap-Penalties in Sequence-Alignment Approach to Polymorphic Virus Detection
Journal of Information Security, 2017, 8, 296-327 http://www.scirp.org/journal/jis ISSN Online: 2153-1242 ISSN Print: 2153-1234 Exploring the Effects of Gap-Penalties in Sequence-Alignment Approach to Polymorphic Virus Detection Vijay Naidu*, Jacqueline Whalley, Ajit Narayanan School of Engineering, Computer and Mathematical Sciences, Auckland University of Technology, Auckland, New Zealand How to cite this paper: Naidu, V., Whal- Abstract ley, J. and Narayanan, A. (2017) Exploring the Effects of Gap-Penalties in Sequence- Antiviral software systems (AVSs) have problems in identifying polymorphic Alignment Approach to Polymorphic Virus variants of viruses without explicit signatures for such variants. Align- Detection. Journal of Information Security, ment-based techniques from bioinformatics may provide a novel way to gen- 8, 296-327. https://doi.org/10.4236/jis.2017.84020 erate signatures from consensuses found in polymorphic variant code. We demonstrate how multiple sequence alignment supplemented with gap penal- Received: August 1, 2017 ties leads to viral code signatures that generalize successfully to previously Accepted: October 16, 2017 Published: October 19, 2017 known polymorphic variants of JS. Cassandra virus and previously unknown polymorphic variants of W32.CTX/W32.Cholera and W32.Kitti viruses. The Copyright © 2017 by authors and implications are that future smart AVSs may be able to generate effective sig- Scientific Research Publishing Inc. natures automatically from actual viral code by varying gap penalties to cover This work is licensed under the Creative Commons Attribution International for both known and unknown polymorphic variants. License (CC BY 4.0). http://creativecommons.org/licenses/by/4.0/ Keywords Open Access Polymorphic Malware Variants, Gap Penalties, Syntactic Approach, Pairwise Sequence Alignment, Multiple Sequence Alignment, Automatic Signature Generation, Smith-Waterman Algorithm, JS.
[Show full text]