<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE ArticleSet PUBLIC "-//NLM//DTD PubMed 2.7//EN" "https://dtd.nlm.nih.gov/ncbi/pubmed/in/PubMed.dtd">
<ArticleSet>
<Article>
<Journal>
				<PublisherName>University of Tabriz</PublisherName>
				<JournalTitle>Tabriz Journal of Electrical Engineering</JournalTitle>
				<Issn>2008-7799</Issn>
				<Volume>50</Volume>
				<Issue>4</Issue>
				<PubDate PubStatus="epublish">
					<Year>2021</Year>
					<Month>02</Month>
					<Day>19</Day>
				</PubDate>
			</Journal>
<ArticleTitle>An Efficient Approach for Unknown Malware Detection Based on Opcode Analysis</ArticleTitle>
<VernacularTitle>An Efficient Approach for Unknown Malware Detection Based on Opcode Analysis</VernacularTitle>
			<FirstPage>1847</FirstPage>
			<LastPage>1864</LastPage>
			<ELocationID EIdType="pii">12462</ELocationID>
			
			
			<Language>FA</Language>
<AuthorList>
<Author>
					<FirstName>F.</FirstName>
					<LastName>Manavi</LastName>
<Affiliation>Faculty of Electrical and Computer Engineering, University of Shiraz, Shiraz, Iran</Affiliation>

</Author>
<Author>
					<FirstName>A.</FirstName>
					<LastName>Hamzeh</LastName>
<Affiliation>Faculty of Electrical and Computer Engineering, University of Shiraz, Shiraz, Iran</Affiliation>

</Author>
</AuthorList>
				<PublicationType>Journal Article</PublicationType>
			<History>
				<PubDate PubStatus="received">
					<Year>2019</Year>
					<Month>01</Month>
					<Day>06</Day>
				</PubDate>
			</History>
		<Abstract>Today, with the development of computer systems, malware has grown dramatically. Malware is defined as a program that is developed with malicious purpose, such as sabotaging the computer system, information theft or other malicious actions. Malware detection is a branch of computer security which attempts to analyze suspicious programs, detect malware and ultimately eliminate the threat. Opcode-based methods are commonly used in malware detection. Given that, all Opcode are not important for detecting malware, some of them can be ignored in the detection process. In this research, the proposed method is based on Opcode Analysis, but only some of the important and effective Opcodes will be considered for file detection. First, momentous Opcodes of file are identified and employed for generating images. Then, features are extracted from the images in order to accomplish the classification. The advantage of the proposed method is that images are created based on important Opcodes and detecting malware is converted into image classification. Therefore, the proposed method is more optimized compared to the previous methods and also has acceptable accuracy and less complexity.</Abstract>
			<OtherAbstract Language="FA">Today, with the development of computer systems, malware has grown dramatically. Malware is defined as a program that is developed with malicious purpose, such as sabotaging the computer system, information theft or other malicious actions. Malware detection is a branch of computer security which attempts to analyze suspicious programs, detect malware and ultimately eliminate the threat. Opcode-based methods are commonly used in malware detection. Given that, all Opcode are not important for detecting malware, some of them can be ignored in the detection process. In this research, the proposed method is based on Opcode Analysis, but only some of the important and effective Opcodes will be considered for file detection. First, momentous Opcodes of file are identified and employed for generating images. Then, features are extracted from the images in order to accomplish the classification. The advantage of the proposed method is that images are created based on important Opcodes and detecting malware is converted into image classification. Therefore, the proposed method is more optimized compared to the previous methods and also has acceptable accuracy and less complexity.</OtherAbstract>
		<ObjectList>
			<Object Type="keyword">
			<Param Name="value">classification</Param>
			</Object>
			<Object Type="keyword">
			<Param Name="value">image</Param>
			</Object>
			<Object Type="keyword">
			<Param Name="value">malware</Param>
			</Object>
			<Object Type="keyword">
			<Param Name="value">malware detection</Param>
			</Object>
			<Object Type="keyword">
			<Param Name="value">opcode</Param>
			</Object>
		</ObjectList>
<ArchiveCopySource DocType="pdf">https://tjee.tabrizu.ac.ir/article_12462_48c04e557ce2ea9f2f6d839c69433b37.pdf</ArchiveCopySource>
</Article>
</ArticleSet>
