Malware variants detection based on ensemble learning

被引:0
|
作者
Ma Yan [1 ]
Du Donggao [1 ,2 ]
机构
[1] Network and Information Center,Institute of Network Technology,Beijing University of Posts and Telecommunications
[2] National Engineering Laboratory for Mobile Network Security,Beijing University of Post and Telecommunications
基金
中国国家自然科学基金;
关键词
D O I
10.19682/j.cnki.1005-8885.2020.1010
中图分类号
TP311.5 [软件工程]; TP309 [安全保密];
学科分类号
081201 ; 081202 ; 0835 ; 0839 ; 1402 ;
摘要
Application programming interface(API) is a procedure call interface to operation system resource. API-based behavior features can capture the malicious behaviors of malware variants. However, existing malware detection approaches have a deal of complex operations on constructing and matching. Furthermore, graph matching is adopted in many approaches, which is a nondeterministic polynominal(NP)-complete problem because of computational complexity. To address these problems, a novel approach is proposed to detect malware variants. Firstly, the API of the malware are divided by their functions and parameters. Then, the classified behavior graph(CBG) is constructed from the API call sequences. Finally, the signature based on CBGs for each malware family is generated. Besides, the malware variants are classified by ensemble learning algorithm. Experiments on 1 220 malware samples show that the true positive rate(TPR) is up to 89.0% with the low false positive rate(FPR) 3.7% by ensemble learning.
引用
收藏
页码:82 / 90
页数:9
相关论文
共 50 条
  • [1] A Malware Detection Method Based on Machine Learning and Ensemble of Regression Trees
    Li, Xinghua
    Li, Xiaolong
    Wang, Feng
    Li, Wenna
    Li, Ang
    [J]. PROCEEDINGS OF 2021 2ND INTERNATIONAL CONFERENCE ON ARTIFICIAL INTELLIGENCE AND INFORMATION SYSTEMS (ICAIIS '21), 2021,
  • [2] A Robust Malware Detection Approach for Android System Based on Ensemble Learning
    Li, Wenjia
    Cai, Juecong
    Wang, Zi
    Cheng, Sihua
    [J]. UBIQUITOUS SECURITY, 2022, 1557 : 309 - 321
  • [3] DroidExaminer: An Android Malware Hybrid Detection System Based on Ensemble Learning
    Zhan, Zhongxiang
    Ji, Sai
    Zheng, Wenying
    Liu, Dengzhi
    [J]. JOURNAL OF INTERNET TECHNOLOGY, 2024, 25 (01): : 105 - 116
  • [4] SMASH: A Malware Detection Method Based on Multi-Feature Ensemble Learning
    Dai, Yusheng
    Li, Hui
    Qian, Yekui
    Yang, Ruipeng
    Zheng, Min
    [J]. IEEE ACCESS, 2019, 7 : 112588 - 112597
  • [5] Windows PE Malware Detection Using Ensemble Learning
    Azeez, Nureni Ayofe
    Odufuwa, Oluwanifise Ebunoluwa
    Misra, Sanjay
    Oluranti, Jonathan
    Damasevicius, Robertas
    [J]. INFORMATICS-BASEL, 2021, 8 (01):
  • [6] An Effective Ensemble Deep Learning Framework for Malware Detection
    Dinh Viet Sang
    Dang Manh Cuong
    Le Tran Bao Cuong
    [J]. PROCEEDINGS OF THE NINTH INTERNATIONAL SYMPOSIUM ON INFORMATION AND COMMUNICATION TECHNOLOGY (SOICT 2018), 2018, : 192 - 199
  • [7] Optimizing android malware detection via ensemble learning
    Christiana, Abikoye Oluwakemi
    Gyunka, Benjamin Aruwa
    Oluwatobi, Akande Noah
    [J]. International Journal of Interactive Mobile Technologies, 2020, 14 (09) : 61 - 78
  • [8] A new deep boosted CNN and ensemble learning based IoT malware detection
    Khan, Saddam Hussain
    Alahmadi, Tahani Jaser
    Ullah, Wasi
    Iqbal, Javed
    Rahim, Azizur
    Alkahtani, Hend Khalid
    Alghamdi, Wajdi
    Almagrabi, Alaa Omran
    [J]. COMPUTERS & SECURITY, 2023, 133
  • [9] Android Malware Detection Using Ensemble Feature Learning
    Rout, Siddhartha Suman
    Vashishtha, Lalit Kumar
    Chatterjee, Kakali
    Rout, Jitendra Kumar
    [J]. INFORMATION SYSTEMS AND MANAGEMENT SCIENCE, ISMS 2021, 2023, 521 : 531 - 539
  • [10] Malware Detection based on Dynamic Multi-feature using Ensemble Learning at Hypervisor
    Zhang, Jian
    Gao, Cheng
    Gong, Liangyi
    Gu, Zhaojun
    Man, Dapeng
    Yang, Wu
    Du, Xiaojiang
    [J]. 2018 IEEE GLOBAL COMMUNICATIONS CONFERENCE (GLOBECOM), 2018,