Using a Subtractive Center Behavioral Model to Detect Malware

Author:

Aslan Ömer12ORCID,Samet Refik1ORCID,Tanrıöver Ömer Özgür1ORCID

Affiliation:

1. Ankara University, Computer Engineering Department, Ankara 06830, Turkey

2. Siirt University, Computer Engineering Department, Siirt 56100, Turkey

Abstract

In recent years, malware has evolved by using different obfuscation techniques; due to this evolution, the detection of malware has become problematic. Signature-based and traditional behavior-based malware detectors cannot effectively detect this new generation of malware. This paper proposes a subtractive center behavior model (SCBM) to create a malware dataset that captures semantically related behaviors from sample programs. In the proposed model, system paths, where malware behaviors are performed, and malware behaviors themselves are taken into consideration. This way malicious behavior patterns are differentiated from benign behavior patterns. Features that could not exceed the specified score are removed from the dataset. The datasets created using the proposed model contain far fewer features than the datasets created by n-gram and other models that have been used in other studies. The proposed model can handle both known and unknown malware, and the obtained detection rate and accuracy of the proposed model are higher than those of the known models. To show the effectiveness of the proposed model, 2 datasets with score and without score are created by using SCBM. In total, 6700 malware samples and 3000 benign samples are tested. The results are compared with those derived from n-gram and models from other studies in the literature. The test results show that, by combining the proposed model with an appropriate machine learning algorithm, the detection rate, false positive rate, and accuracy are measured as 99.9%, 0.2%, and 99.8%, respectively.

Publisher

Hindawi Limited

Subject

Computer Networks and Communications,Information Systems

Cited by 13 articles. 订阅此论文施引文献 订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献

1. Veri setine uygulanan ön işlemler ile makine öğrenimi yöntemi kullanılarak geliştirilen saldırı tespit modellerinin performanslarının arttırılması;Gazi Üniversitesi Mühendislik Mimarlık Fakültesi Dergisi;2023-11-30

2. A Method for Summarizing and Classifying Evasive Malware;Proceedings of the 26th International Symposium on Research in Attacks, Intrusions and Defenses;2023-10-16

3. A Kullback-Liebler divergence-based representation algorithm for malware detection;PeerJ Computer Science;2023-09-22

4. A Comprehensive Review of Cyber Security Vulnerabilities, Threats, Attacks, and Solutions;Electronics;2023-03-11

5. Disparity Analysis Between the Assembly and Byte Malware Samples with Deep Autoencoders;2022 19th International Computer Conference on Wavelet Active Media Technology and Information Processing (ICCWAMTIP);2022-12-16

同舟云学术

1.学者识别学者识别

2.学术分析学术分析

3.人才评估人才评估

"同舟云学术"是以全球学者为主线,采集、加工和组织学术论文而形成的新型学术文献查询和分析系统,可以对全球学者进行文献检索和人才价值评估。用户可以通过关注某些学科领域的顶尖人物而持续追踪该领域的学科进展和研究前沿。经过近期的数据扩容,当前同舟云学术共收录了国内外主流学术期刊6万余种,收集的期刊论文及会议论文总量共计约1.5亿篇,并以每天添加12000余篇中外论文的速度递增。我们也可以为用户提供个性化、定制化的学者数据。欢迎来电咨询!咨询电话:010-8811{复制后删除}0370

www.globalauthorid.com

TOP

Copyright © 2019-2024 北京同舟云网络信息技术有限公司
京公网安备11010802033243号  京ICP备18003416号-3