Friday, July 25, 2014

Similarity matrix - behavioral malware clusters





 

In this similarity matrix, we can see a diagonal line of red boxes, which decrease in size from left to right.  These red boxes represent a strong similarity (close to identical).  The diagonal line of red boxes is surrounded by mostly blue boxes – this color indicates small similarity.  These similarity matrices can be used for various purposes; this one is being used to determine malware behavioral patterns, and hopefully to predict future patterns by their similarities.

No comments:

Post a Comment