Research Article

A Malware Detection Scheme Based on Mining Format Information

Table 4

The mean values of selected features.

Name of featureMean values
Features selected by CfsSubsetEvalFeatures selected by WrapperSubsetEvalMalwareBenign software

SizeOfDebugDataSizeOfDebugData0.98222.6
ImageBaseImageBase1.7 × 1077.6 × 108
SizeOfCertificateTableSizeOfCertificateTable8.872.8 × 103
DllCharacteristicsDllCharacteristics29.83.6 × 103
.reloc.characteristics.reloc.characteristics7.4 × 1089.3 × 108
SizeOfLoadConfigurationTable1.0 × 10522.7
NumberOfVERSIONNumberOfVERSION0.4080.95
CharacteristicsCharacteristics1.5 × 1047.1 × 103
GetModuleHandle0.0010.23
AddressOfDebugData3 × 1031.4 × 105
lstrlenW0.0050.296
DisableThreadLibraryCall0.0030.253
.rsrc.characteristics1.4 × 1091.0 × 109
CreateFileW0.0020.204
_initterm0.0360.416
RegDeleteKey00.1
__adjust_fdiv0.0350.415
mscoree.dllmscoree.dll0.0020.189
NumberOfGROUP ICON0.8791.204
BaseOfCode7.3 × 1047.8 × 103
wsock32.dllwsock32.dll0.2590.016
.text.Characteristics1.4 × 1091.5 × 109
.rdata.Characteristics6.2 × 1083.5 × 108
NumberOfMESSAGE TABLE0.0020.057
NumberofAPIsNumberofAPIs65.197.1
SizeOfHeapReserve1.5 × 1061.0 × 106
imm32.dll0.0010.013
NumberOfSymbols3.1 × 10615.9
Numberofsections4.84.1