Research Article

A Data Mining Classification Approach for Behavioral Malware Detection

Box 2

An example of standard form for WEKA input.
@RELATION TEST    file name
@ATTRIBUTE dll1     numeric     property
@ATTRIBUTE dll2     numeric     property
@ATTRIBUTE dll3     numeric     property
@ATTRIBUTE dll4     numeric     property
…………………               property
@ATTRIBUTE param88   numeric        property
@ATTRIBUTE class     Answer - property
@DATA
0 1.068, 2 0.534, 8 0.534, 11 0.534, 12 0.534, 23 0.534, 32 0.534, 33 0.534, 35 ……….