FENOC: An Ensemble One-Class Learning Framework for Malware Detection

被引:8
|
作者
Liu, Jiachen [1 ]
Song, Jianfeng [1 ]
Miao, Qiguang [1 ]
Cao, Ying [1 ]
机构
[1] Xidian Univ, Sch Comp Sci & Technol, Xian, Peoples R China
关键词
malware detection; malware feature; one-class classification; ensemble learning; EXECUTABLES;
D O I
10.1109/CIS.2013.116
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Nowadays, machine learning based methods are among the most popular ones for malware detection. However, most of the previous works use a single type of features, dynamic or static, and take them to build a binary classification model. These methods have limited ability to depict characteristic malware behaviors and suffer from insufficiently sampled benign samples and extremely imbalanced training dataset. In this paper, we present FENOC, an ensemble one-class learning framework for malware detection. FENOC uses hybrid features from multiple semantic layers to ensure comprehensive insights of analyzed programs, and constructs detection model via CosTOC (Cost-sensitive Twin One-class Classifier), a novel one-class learning algorithm, which uses a pair of one-class classifiers to describe malware class and benign program class respectively. CosTOC is more flexible and robust when handling malware detection problems, which is imbalanced and need low false positive rate. Meanwhile, a random subspace ensemble method is used to enhance the generalization ability of CosTOC. Experimental results show that to detect unknown malware, FENOC has a higher detection rate and a lower false positive rate, especially in the situations that training datasets are imbalanced.
引用
收藏
页码:523 / 527
页数:5
相关论文
共 50 条
  • [1] An Ensemble Cost-Sensitive One-Class Learning Framework for Malware Detection
    Liu, Jia-Chen
    Song, Jian-Feng
    Miao, Qi-Guang
    Cao, Ying
    Quan, Yi-Ning
    [J]. INTERNATIONAL JOURNAL OF PATTERN RECOGNITION AND ARTIFICIAL INTELLIGENCE, 2015, 29 (05)
  • [2] Malware Detection With Subspace Learning-Based One-Class Classification
    Al-Khshali, Hasan H.
    Ilyas, Muhammad
    Sohrab, Fahad
    Gabbouj, Moncef
    [J]. IEEE ACCESS, 2024, 12 : 81017 - 81029
  • [3] RAMD: registry-based anomaly malware detection using one-class ensemble classifiers
    Asghar Tajoddin
    Mahdi Abadi
    [J]. Applied Intelligence, 2019, 49 : 2641 - 2658
  • [4] RAMD: registry-based anomaly malware detection using one-class ensemble classifiers
    Tajoddin, Asghar
    Abadi, Mahdi
    [J]. APPLIED INTELLIGENCE, 2019, 49 (07) : 2641 - 2658
  • [5] Malware Detection for Internet of Things Using One-Class Classification
    Shi, Tongxin
    McCann, Roy A.
    Huang, Ying
    Wang, Wei
    Kong, Jun
    [J]. SENSORS, 2024, 24 (13)
  • [6] An Effective Ensemble Deep Learning Framework for Malware Detection
    Dinh Viet Sang
    Dang Manh Cuong
    Le Tran Bao Cuong
    [J]. PROCEEDINGS OF THE NINTH INTERNATIONAL SYMPOSIUM ON INFORMATION AND COMMUNICATION TECHNOLOGY (SOICT 2018), 2018, : 192 - 199
  • [7] One-Class SVM with Privileged Information and its Application to Malware Detection
    Burnaev, Evgeny
    Smolyakov, Dmitry
    [J]. 2016 IEEE 16TH INTERNATIONAL CONFERENCE ON DATA MINING WORKSHOPS (ICDMW), 2016, : 273 - 280
  • [8] Incipient fault detection with feature ensemble based on one-class machine learning methods
    Wang, Min
    Cheng, Feiyang
    Chen, Kai
    Mi, Jinhua
    Xu, Zhiwei
    Qiu, Gen
    [J]. 2023 62ND IEEE CONFERENCE ON DECISION AND CONTROL, CDC, 2023, : 4867 - 4872
  • [9] Effective One-Class Classifier Model for Memory Dump Malware Detection
    Al-Qudah, Mahmoud
    Ashi, Zein
    Alnabhan, Mohammad
    Abu Al-Haija, Qasem
    [J]. JOURNAL OF SENSOR AND ACTUATOR NETWORKS, 2023, 12 (01)
  • [10] An ensemble learning algorithm for one-class classification of hyperspectral images
    Wang, Xiaofei
    Yan, Qiujing
    [J]. Guangxue Xuebao/Acta Optica Sinica, 2014, 34