Research Article

A Malware Detection Scheme Based on Mining Format Information

Table 2

List of the features extracted from PE files.

Feature descriptionTypeQuantity

DLLs referredInteger30
APIs referredInteger30
The number of DLLs referredInteger1
The number of APIs referredInteger1
The number of sectionsInteger1
The number of symbols in export tableInteger1
The number of items in reloc sectionInteger1
Dos header—e_lfanewInteger1
IMAGE_FILE_HEADERInteger5
IMAGE_OPTIONAL_HEADERInteger16
IMAGE_DATA_DIRECTORYInteger32
.text section—header fieldInteger11
.data section—header fieldInteger11
.rsrc section—header fieldInteger11
.rdata section—header fieldInteger11
.reloc section—header fieldInteger11
Resource directory table and resourcesInteger23

Total197