Proceedings Article10.1109/CSCI49370.2019.00022
Static Malware Analysis Using Machine Learning Algorithms on APT1 Dataset with String and PE Header Features
Neil Balram,George Hsieh,Christian McFall +2 more
- 01 Dec 2019
- pp 90-95
19
TL;DR: This paper presents the design and implementation of six different machine learning classifiers, and two distinct categories of features statically extracted from the executables: strings and Portable Executable header information.
read more
Abstract: Static malware analysis is used to analyze executable files without executing the code to determine whether a file is malicious or not. Data analytic and machine learning techniques have been used increasingly to help process the large number of malware files circulating in the wild and detect new attacks. In this paper, we present the design and implementation of six different machine learning classifiers, and two distinct categories of features statically extracted from the executables: strings and Portable Executable header information. A total of twelve malware detectors were implemented for each of the six classifiers to operate with each of the two feature categories separately. These classifiers and feature extraction algorithms were implemented in Python using the scikit-learn machine learning library. The performances in detection accuracy and required processing time of the twelve malware detectors were compared and analyzed.
read more
Chat with Paper
AI Agents for this Paper
Find similar papers on Google Scholar, PubMed and Arxiv
Write a critical review of this paper
Analyze citations of this paper to find unaddressed research gaps
Citations
Data-Driven Malware Detection for 6G Networks: A Survey From the Perspective of Continuous Learning and Explainability via Visualisation
01 Jan 2023
TL;DR: In this article , the authors review the theoretical and experimental data-driven malware detection literature, in the large-scale data-intensive field, relating to: (1) continuous learning, including new concepts in multi-domain to multi-target learning and (2) new explainability via visualisation concepts with a multi-labelling approach which allows identifying malware by their recipes while improving the interpretability of its decision process.
17
Applications of Machine Learning in Digital Forensics
Sana Qadir,Basirah Noor +1 more
- 20 May 2021
TL;DR: In this article, a wide range of publications mentioning ML based techniques that can be used to ease the process of digital forensics principally in the field of malware, network forensics, image/video forensics and mobile/memory forensics.
14
Malware detection and classification using community detection and social network analysis
TL;DR: The combined approach outperforms many previously used methods in malware detection and classification, being able to achieve precision, recall, and accuracy of more than 0.97 using Multilayer Perceptron and k-Nearest Neighbors.
10
Static Malware Analysis Using Low-Parameter Machine Learning Models
Ryan Baker del Aguila,Carlos Daniel Contreras Pérez,Alejandra Guadalupe Silva Trujillo,Juan C. Cuevas-Tello,J. Nuñez-Varela +4 more
TL;DR: This study evaluates the efficacy of memory-optimized machine learning models (ANN, SVM, GBM) for static malware analysis, finding that artificial neural networks (ANNs) achieve 93.44% accuracy in classifying programs as malware or legitimate under extreme memory constraints.
5
References
Deep Learning Approach to Malware Multi-class Classification Using Image Processing Techniques
Mamta Kumari,George Hsieh,Christopher A. Okonkwo +2 more
- 01 Dec 2017
TL;DR: The design and implementation of a malware classification approach using the Convolutional Neural Networks (CNNs), a prime example of deep learning algorithms, makes use of CNNs to learn a feature hierarchy for classifying samples of malware binary files to their corresponding families.
6
•Book
Spyware Detection: Using Data mining for Windows Portable Executable Files
Fadel Omar Shaban
- 20 Nov 2013
TL;DR: This thesis would not exist without the help, advice, support, guidance, and encouragement of many people who have one way or another helped me in making this study a success.
5
Comparative Analysis of Feature Extraction Methods of Malware Detection
Smita Ranveer,Swapnaja Hiray +1 more
TL;DR: This paper highlights general framework of malware detection system and pinpoints strengths and weaknesses of each method and presented overview of performance of present malware detection systems based on features.
Opcodes as predictor for malware
TL;DR: It is found that malware opcode distributions differ statistically significantly from non-malicious software, and rare opcodes seem to be a stronger predictor, explaining 12 63% of frequency variation.