A novel machine learning approach for detecting first-time-appeared malware

被引:15
|
作者
Shaukat, Kamran [1 ,2 ,3 ]
Luo, Suhuai [2 ]
Varadharajan, Vijay [4 ]
机构
[1] Torrens Univ, Ctr Artificial Intelligence Res & Optimizat AIRO, Design & Creat Technol Vert, Ultimo, NSW 2007, Australia
[2] Univ Newcastle, Sch Informat & Phys Sci, Callaghan, Australia
[3] Univ Punjab, Dept Data Sci, Lahore 54890, Pakistan
[4] Univ Newcastle, Adv Cyber Secur Engn Res Ctr ACSRC, Callaghan, Australia
关键词
Deep learning; Machine learning; Artificial intelligence; Zero -day malware; Polymorphic; Malware; Cybersecurity; Evolving attacks; Security analytics; CLASSIFICATION;
D O I
10.1016/j.engappai.2023.107801
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Conventional malware detection approaches have the overhead of feature extraction, the requirement of domain experts, and are time-consuming and resource-intensive. Learning-based approaches are the mainstay of malware detection as they overcome most of these challenges by significantly improving the detection effectiveness and providing a low false positive rate. The exponential growth of malware variants and first-time-appeared malware, which includes polymorphic and zero-day attacks, are some of the significant challenges to learning-based malware detectors. These challenges have catastrophic impacts on the detection effectiveness of these learningbased malware detectors. This paper proposes a novel deep learning-based framework to detect first-timeappeared malware effectively and efficiently by providing better performance than conventional malware detection approaches. First, it translates and visualises each Windows portable executable (PE) file into a coloured image to eliminate the overhead of feature extraction and the need for domain experts to analyse the features. In the subsequent step, a fine-tuned deep learning model is used to extract the deep features from the last fully connected layer. The step has reduced the cost of training required by the deep learning models if used for end-to-end classification. The third step selects the most important and influential features through a powerful feature selection algorithm. The most important features are then fed to a one-class classifier for final detection. With the one-class classifier, an enclosed boundary around the features of benign data is constructed. Anything outside the boundary is declared as an anomaly/malicious. It has enhanced the framework's ability to detect evolving, unseen, polymorphic, and zero-day attacks, as well as reducing the problem of overfitting. The detection effectiveness of the proposed framework is validated with state-of-the-art deep learning models and conventional approaches. The proposed framework has outperformed with an accuracy of 99.30% on the Malimg dataset. The Wilcoxon signed-rank test is used to validate the statistical significance of the proposed framework. It is evident from the results that the proposed framework is effective and can be used in the defence industry, resulting in more powerful and robust solutions against zero-day and polymorphic attacks.
引用
收藏
页数:17
相关论文
共 50 条
  • [41] A Novel Malware Detection System Based On Machine Learning and Binary Visualization
    Baptista, Irina
    Shiaeles, Stavros
    Kolokotronis, Nicholas
    2019 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS WORKSHOPS (ICC WORKSHOPS), 2019,
  • [42] Hybrid malware detection approach with feedback-directed machine learning
    Zhetao Li
    Wenlin Li
    Fuyuan Lin
    Yi Sun
    Min Yang
    Yuan Zhang
    Zhibo Wang
    Science China Information Sciences, 2020, 63
  • [43] On the Evaluation of the Machine Learning Based Hybrid Approach for Android Malware Detection
    Ratyal, Natasha Javed
    Khadam, Maryam
    Aleem, Muhammad
    2019 22ND IEEE INTERNATIONAL MULTI TOPIC CONFERENCE (INMIC), 2019, : 100 - 107
  • [44] Hybrid malware detection approach with feedback-directed machine learning
    Li, Zhetao
    Li, Wenlin
    Lin, Fuyuan
    Sun, Yi
    Yang, Min
    Zhang, Yuan
    Wang, Zhibo
    SCIENCE CHINA-INFORMATION SCIENCES, 2020, 63 (03)
  • [45] Macro Malware Detection using Machine Learning Techniques A New Approach
    De los Santos, Sergio
    Torres, Jose
    ICISSP: PROCEEDINGS OF THE 3RD INTERNATIONAL CONFERENCE ON INFORMATION SYSTEMS SECURITY AND PRIVACY, 2017, : 295 - 302
  • [46] Hybrid malware detection approach with feedback-directed machine learning
    Zhetao LI
    Wenlin LI
    Fuyuan LIN
    Yi SUN
    Min YANG
    Yuan ZHANG
    Zhibo WANG
    Science China(Information Sciences), 2020, 63 (03) : 240 - 242
  • [47] A multi-dimensional machine learning approach to predict advanced malware
    Bahtiyar, Serif
    Yaman, Mehmet Baris
    Altinigne, Can Yilmaz
    COMPUTER NETWORKS, 2019, 160 : 118 - 129
  • [48] A novel deep learning-based approach for malware detection
    Shaukat, Kamran
    Luo, Suhuai
    Varadharajan, Vijay
    ENGINEERING APPLICATIONS OF ARTIFICIAL INTELLIGENCE, 2023, 122
  • [49] A machine learning approach to detecting cracks in levees and floodwalls
    Kuchi, Aditi
    Panta, Manisha
    Hoque, Md Tamjidul
    Abdelguerfi, Mahdi
    Flanagin, Maik C.
    REMOTE SENSING APPLICATIONS-SOCIETY AND ENVIRONMENT, 2021, 22
  • [50] Machine Learning Approach for Detecting Location Spoofing in VANET
    Sharma, Aekta
    Jaekel, Arunita
    30TH INTERNATIONAL CONFERENCE ON COMPUTER COMMUNICATIONS AND NETWORKS (ICCCN 2021), 2021,