Key points are not available for this paper at this time.
Traditional signature-based malware detection techniques have been used for many years owing to their high detection rates and low false positive rates. However, signature-based techniques are ineffective as they do not detect new, polymorphic or transient malware. To beat weaknesses in signature-detection techniques, researchers have turned to behaviour-based ones, which create a malware behaviour profile by capturing malicious API calls throughout execution. In this context, API matching techniques use API calls to calculate similarities between malware. However, API concatenation techniques need significant API call process resources, which makes these methods slow owing to process quality, and thus cannot scale to large API call sequences outside the lab. In this paper, we review present malware detection strategies supported by API call sequences.
Fahad Mira (Wed,) studied this question.