A scalable approach for malware detection through bounded feature space behavior modeling
Mahinthan Chandramohan,Hee Beng Kuan Tan,Lionel C. Briand,Lwin Khin Shar,Bindu Madhavi Padmanabhuni +4 more
- 11 Nov 2013
- pp 312-322
TL;DR: This paper proposes and evaluates a bounded feature space behavior modeling (BOFM) framework for scalable malware detection, and shows that its computation time and memory usage are vastly lower than in currently reported, malware detection techniques, while preserving or even improving their high detection accuracy.
read more
Abstract: In recent years, malware (malicious software) has greatly evolved and has become very sophisticated. The evolution of malware makes it difficult to detect using traditional signature-based malware detectors. Thus, researchers have proposed various behavior-based malware detection techniques to mitigate this problem. However, there are still serious shortcomings, related to scalability and computational complexity, in existing malware behavior modeling techniques. This raises questions about the practical applicability of these techniques. This paper proposes and evaluates a bounded feature space behavior modeling (BOFM) framework for scalable malware detection. BOFM models the interactions between software (which can be malware or benign) and security-critical OS resources in a scalable manner. Information collected at run-time according to this model is then used by machine learning algorithms to learn how to accurately classify software as malware or benign. One of the key problems with simple malware behavior modeling (e.g., n-gram model) is that the number of malware features (i.e., signatures) grows proportional to the size of execution traces, with a resulting malware feature space that is so large that it makes the detection process very challenging. On the other hand, in BOFM, the malware feature space is bounded by an upper limit N, a constant, and the results of our experiments show that its computation time and memory usage are vastly lower than in currently reported, malware detection techniques, while preserving or even improving their high detection accuracy.
read more
Chat with Paper
AI Agents for this Paper
Find similar papers on Google Scholar, PubMed and Arxiv
Write a critical review of this paper
Analyze citations of this paper to find unaddressed research gaps
Citations
A Comprehensive Review on Malware Detection Approaches
Omer Aslan,Refik Samet +1 more
TL;DR: This paper presents a detailed review on malware detection approaches and recent detection methods which use these approaches, and the pros and cons of each detection approach, and methods that are used in these approaches.
Semantics-Based Online Malware Detection: Towards Efficient Real-Time Protection Against Malware
TL;DR: GuardOL is a combined approach using processor and field-programmable gate array (FPGA) to perform online malware detection and aims to capture the malicious behavior (i.e., high-level semantics) of malware.
194
Review: machine learning techniques applied to cybersecurity
TL;DR: This work presents the importance of different error criteria as the confusion matrix or mean absolute error in classification problems, and relative error in regression problems.
145
A New Malware Classification Framework Based on Deep Learning Algorithms
Omer Aslan,Abdullah Asim Yilmaz +1 more
TL;DR: In this paper, a novel deep learning-based architecture is proposed which can classify malware variants based on a hybrid model, which integrates two wide-ranging pre-trained network models in an optimized manner.
Malware Detection Based on Deep Learning of Behavior Graphs
TL;DR: A novel behavior-based deep learning framework (BDLF) which is built in cloud platform for detecting malware in IoT environment and can learn the semantics of higher-level malicious behaviors from behavior graphs and increase the average detection precision by 1.5%.
References
The WEKA data mining software: an update
TL;DR: This paper provides an introduction to the WEKA workbench, reviews the history of the project, and, in light of the recent 3.6 stable release, briefly discusses what has been added since the last stable version (Weka 3.4) released in 2003.
•Book
Support Vector Machines
Ingo Steinwart,Andreas Christmann +1 more
- 12 Aug 2008
TL;DR: This book explains the principles that make support vector machines (SVMs) a successful modelling and prediction tool for a variety of applications and provides a unique in-depth treatment of both fundamental and recent material on SVMs that so far has been scattered in the literature.
6.1K
Applied Logistic Regression Analysis
Abstract: Series Editor's Introduction Author's Introduction to the Second Edition 1. Linear Regression and Logistic Regression Model 2. Summary Statistics for Evaluating the Logistic Regression Model 3. Interpreting the Logistic Regression Coefficients 4. An Introduction to Logistic Regression Diagnosis Ch 5. Polytomous Logistic Regression and Alternatives to Logistic Regression 6. Notes Appendix A References Tables Figures
4.5K
•Book
Applied Logistic Regression Analysis
Scott Menard
- 09 Oct 2001
TL;DR: The second edition of the Second Edition of the Logistic regression model as discussed by the authors is the most complete version of the first edition and includes a discussion of the relationship between linear regression and logistic regression.
4.5K
Limits of Static Analysis for Malware Detection
Andreas Moser,Christopher Kruegel,Engin Kirda +2 more
- 01 Dec 2007
TL;DR: A binary obfuscation scheme that relies on opaque constants, which are primitives that allow us to load a constant into a register such that an analysis tool cannot determine its value, demonstrates that static analysis techniques alone might no longer be sufficient to identify malware.