A post-mortem empirical investigation of the popularity and distribution of malware files in the contemporary web-facing internet

Jukka Ruohonen, Sanja Scepanovic, Sami Hyrynsalmi, Igor Mishkovski, Tuomas Aura, Ville Leppanen

Tutkimustuotos: Artikkeli kirjassa/konferenssijulkaisussaConference contributionScientificvertaisarvioitu

1 Sitaatiot (Scopus)

Abstrakti

This short empirical paper investigates a snapshot of about two million files from a continuously updated big data collection maintained by F-Secure for security intelligence purposes. By further augmenting the snapshot with open data covering about a half of a million files, the paper examines two questions: (a) what is the shape of a probability distribution characterizing the relative share of malware files to all files distributed from web-facing Internet domains, and (b) what is the distribution shaping the popularity of malware files? A bimodal distribution is proposed as an answer to the former question, while a graph theoretical definition for the popularity concept indicates a long-tailed, extreme value distribution. With these two questions - and the answers thereto, the paper contributes to the attempts to understand large-scale characteristics of malware at the grand population level - at the level of the whole Internet.

AlkuperäiskieliEnglanti
OtsikkoProceedings - 2016 European Intelligence and Security Informatics Conference, EISIC 2016
KustantajaIEEE
Sivut144-147
Sivumäärä4
ISBN (elektroninen)9781509028566
DOI - pysyväislinkit
TilaJulkaistu - 2 maalisk. 2017
OKM-julkaisutyyppiA4 Artikkeli konferenssijulkaisuussa
TapahtumaEuropean Intelligence and Security Informatics Conference - Uppsala, Ruotsi
Kesto: 17 elok. 201619 elok. 2016
Konferenssinumero: 7

Conference

ConferenceEuropean Intelligence and Security Informatics Conference
LyhennettäEISIC
Maa/AlueRuotsi
KaupunkiUppsala
Ajanjakso17/08/201619/08/2016

Sormenjälki

Sukella tutkimusaiheisiin 'A post-mortem empirical investigation of the popularity and distribution of malware files in the contemporary web-facing internet'. Ne muodostavat yhdessä ainutlaatuisen sormenjäljen.

Siteeraa tätä