Research Article
A Malware Detection Scheme Based on Mining Format Information
Table 2
List of the features extracted from PE files.
| Feature description | Type | Quantity |
| DLLs referred | Integer | 30 | APIs referred | Integer | 30 | The number of DLLs referred | Integer | 1 | The number of APIs referred | Integer | 1 | The number of sections | Integer | 1 | The number of symbols in export table | Integer | 1 | The number of items in reloc section | Integer | 1 | Dos header—e_lfanew | Integer | 1 | IMAGE_FILE_HEADER | Integer | 5 | IMAGE_OPTIONAL_HEADER | Integer | 16 | IMAGE_DATA_DIRECTORY | Integer | 32 | .text section—header field | Integer | 11 | .data section—header field | Integer | 11 | .rsrc section—header field | Integer | 11 | .rdata section—header field | Integer | 11 | .reloc section—header field | Integer | 11 | Resource directory table and resources | Integer | 23 |
| Total | 197 |
|
|