Robust Malicious Executable Detection Using Host-Based Machine Learning Classifier

被引:0
|
作者
Soliman, Khaled [1 ]
Sobh, Mohamed [2 ]
Bahaa-Eldin, Ayman M. [2 ]
机构
[1] Ain Shams Univ, Dept Comp & Syst Engn, Cairo 11517, Egypt
[2] ElSewedy Univ Technol, Dept Comp Engn Technol, Cairo 7060010, Egypt
来源
CMC-COMPUTERS MATERIALS & CONTINUA | 2024年 / 79卷 / 01期
关键词
Portable executable; malware; intrusion detection; cybersecurity; zero-day threats; Host Intrusion Detection System (HIDS); machine learning; Anomaly-based Intrusion Detection System (AIDS); deep learning;
D O I
10.32604/cmc.2024.048883
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The continuous development of cyberattacks is threatening digital transformation endeavors worldwide and leads to wide losses for various organizations. These dangers have proven that signature-based approaches are insufficient to prevent emerging and polymorphic attacks. Therefore, this paper is proposing a Robust Malicious Executable Detection (RMED) using Host-based Machine Learning Classifier to discover malicious Portable Executable (PE) files in hosts using Windows operating systems through collecting PE headers and applying machine learning mechanisms to detect unknown infected files. The authors have collected a novel reliable dataset containing 116,031 benign files and 179,071 malware samples from diverse sources to ensure the efficiency of RMED approach. The most effective PE headers that can highly differentiate between benign and malware files were selected to train the model on 15 PE features to speed up the classification process and achieve real-time detection for malicious executables. The evaluation results showed that RMED succeeded in shrinking the classification time to 91 milliseconds for each file while reaching an accuracy of 98.42% with a false positive rate equal to 1.58. In conclusion, this paper contributes to the field of cybersecurity by presenting a comprehensive framework that leverages Artificial Intelligence (AI) methods to proactively detect and prevent cyber-attacks.
引用
收藏
页码:1419 / 1439
页数:21
相关论文
共 50 条
  • [1] A Multi-view Graph Learning Approach for Host-Based Malicious Behavior Detection
    Zhao, Chenfei
    Zhang, Zhe
    Wu, Tiejun
    Fan, Dunqiu
    [J]. DATABASE SYSTEMS FOR ADVANCED APPLICATIONS. DASFAA 2023 INTERNATIONAL WORKSHOPS, BDMS 2023, BDQM 2023, GDMA 2023, BUNDLERS 2023, 2023, 13922 : 283 - 299
  • [2] Host-based Anomaly Detection Using Learning Techniques
    Mustafa, Ahmad
    Solaimani, Mohiuddin
    Khan, Latifur
    Chiang, Ken
    Ingram, Joe
    [J]. 2013 IEEE 13TH INTERNATIONAL CONFERENCE ON DATA MINING WORKSHOPS (ICDMW), 2013, : 1153 - 1160
  • [3] A Study on Detection of Malicious Behavior Based on Host Process Data Using Machine Learning
    Han, Ryeobin
    Kim, Kookjin
    Choi, Byunghun
    Jeong, Youngsik
    [J]. APPLIED SCIENCES-BASEL, 2023, 13 (07):
  • [4] Detecting Malicious Executable Files Based on Static–Dynamic Analysis Using Machine Learning
    R. A. Ognev
    E. V. Zhukovskii
    D. P. Zegzhda
    A. N. Kiselev
    [J]. Automatic Control and Computer Sciences, 2022, 56 : 852 - 864
  • [5] Detecting Malicious Executable Files Based on Static-Dynamic Analysis Using Machine Learning
    Ognev, R. A.
    Zhukovskii, E. V.
    Zegzhda, D. P.
    Kiselev, A. N.
    [J]. AUTOMATIC CONTROL AND COMPUTER SCIENCES, 2022, 56 (08) : 852 - 864
  • [6] Comparison of anomaly detection accuracy of host-based intrusion detection systems based on different machine learning algorithms
    Shin, Yukyung
    Kim, Kangseok
    [J]. International Journal of Advanced Computer Science and Applications, 2020, (02): : 252 - 259
  • [7] Methods for Host-based Intrusion Detection with Deep Learning
    Ring, John H.
    Van Oort, Colin M.
    Durst, Samson
    White, Vanessa
    Near, Joseph P.
    Skalka, Christian
    [J]. Digital Threats: Research and Practice, 2021, 2 (04):
  • [8] Comparison of Anomaly Detection Accuracy of Host-based Intrusion Detection Systems based on Different Machine Learning Algorithms
    Shin, Yukyung
    Kim, Kangseok
    [J]. INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2020, 11 (02) : 252 - 259
  • [9] Detection of malicious URLs using machine learning
    Reyes-Dorta, Nuria
    Caballero-Gil, Pino
    Rosa-Remedios, Carlos
    [J]. WIRELESS NETWORKS, 2024,
  • [10] Ransomware Detection in Executable Files Using Machine Learning
    Ganta, Venkata Gopi
    Harish, G. Venkata
    Kumar, V. Prem
    Rao, G. Rama Koteswar
    [J]. 2020 5TH IEEE INTERNATIONAL CONFERENCE ON RECENT TRENDS ON ELECTRONICS, INFORMATION, COMMUNICATION & TECHNOLOGY (RTEICT-2020), 2020, : 282 - 286