Analysis of Malware Behavior: Type Classification using Machine Learning

被引:0
|
作者
Pirscoveanu, Radu S. [1 ]
Hansen, Steven S. [1 ]
Larsen, Thor M. T. [1 ]
Stevanovic, Matija [1 ]
Pedersen, Jens Myrup [1 ]
Czech, Alexandre [2 ]
机构
[1] Aalborg Univ, Aalborg, Denmark
[2] Ecole Cent Elect, Paris, France
关键词
Malware; type-classification; dynamic analysis; scalability; Cuckoo sandbox; Random Forests; API call; feature selection; supervised machine learning;
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Malicious software has become a major threat to modern society, not only due to the increased complexity of the malware itself but also due to the exponential increase of new malware each day. This study tackles the problem of analyzing and classifying a high amount of malware in a scalable and automatized manner. We have developed a distributed malware testing environment by extending Cuckoo Sandbox that was used to test an extensive number of malware samples and trace their behavioral data. The extracted data was used for the development of a novel type classification approach based on supervised machine learning. The proposed classification approach employs a novel combination of features that achieves a high classification rate with a weighted average AUC value of 0.98 using Random Forests classifier. The approach has been extensively tested on a total of 42,000 malware samples. Based on the above results it is believed that the developed system can be used to pre-filter novel from known malware in a future malware analysis system.
引用
收藏
页数:7
相关论文
共 50 条
  • [1] Analysis of Malware Behavior: Type Classification using Machine Learning
    Pirscoveanu, Radu S.
    Hansen, Steven S.
    Larsen, Thor M. T.
    Stevanovic, Matija
    Pedersen, Jens Myrup
    Czech, Alexandre
    [J]. 2015 International Conference on Cyber Situational Awareness, Data Analytics and Assessment (CyberSA), 2015,
  • [2] Behavior Analysis of Malware Using Machine Learning
    Dhammi, Arshi
    Singh, Maninder
    [J]. 2015 EIGHTH INTERNATIONAL CONFERENCE ON CONTEMPORARY COMPUTING (IC3), 2015, : 481 - 486
  • [3] Malware Classification Using Machine Learning
    Savard, Nolan
    Feinauer, David M.
    Alghazo, Jaafar M.
    Abdelhamid, Sherif E.
    [J]. SOUTHEASTCON 2024, 2024, : 843 - 847
  • [4] Automatic analysis of malware behavior using machine learning
    Rieck, Konrad
    Trinius, Philipp
    Willems, Carsten
    Holz, Thorsten
    [J]. JOURNAL OF COMPUTER SECURITY, 2011, 19 (04) : 639 - 668
  • [5] A Novel Malware Analysis for Malware Detection and Classification using Machine Learning Algorithms
    Sethi, Kamalakanta
    Chaudhary, Shankar Kumar
    Tripathy, Bata Krishan
    Bera, Padmalochan
    [J]. SIN'17: PROCEEDINGS OF THE 10TH INTERNATIONAL CONFERENCE ON SECURITY OF INFORMATION AND NETWORKS, 2017, : 107 - 113
  • [6] Analysis and Classification of Android Malware using Machine Learning Algorithms
    Tarar, Neha
    Sharma, Shweta
    Krishna, C. Rama
    [J]. PROCEEDINGS OF THE 2018 3RD INTERNATIONAL CONFERENCE ON INVENTIVE COMPUTATION TECHNOLOGIES (ICICT 2018), 2018, : 738 - 743
  • [7] A Novel Malware Analysis Framework for Malware Detection and Classification using Machine Learning Approach
    Sethi, Kamalakanta
    Chaudhary, Shankar Kumar
    Tripathy, Bata Krishan
    Bera, Padmalochan
    [J]. ICDCN'18: PROCEEDINGS OF THE 19TH INTERNATIONAL CONFERENCE ON DISTRIBUTED COMPUTING AND NETWORKING, 2018,
  • [8] Runtime-Behavior Based Malware Classification Using Online Machine Learning
    Pektas, Abdurrahman
    Acarman, Tankut
    Falcone, Ylies
    Fernandez, Jean-Claude
    [J]. 2015 WORLD CONGRESS ON INTERNET SECURITY (WORLDCIS), 2015, : 166 - 171
  • [9] Automatic malware classification and new malware detection using machine learning
    Liu Liu
    Bao-sheng Wang
    Bo Yu
    Qiu-xi Zhong
    [J]. Frontiers of Information Technology & Electronic Engineering, 2017, 18 : 1336 - 1347
  • [10] Automatic malware classification and new malware detection using machine learning
    Liu, Liu
    Wang, Bao-sheng
    Yu, Bo
    Zhong, Qiu-xi
    [J]. FRONTIERS OF INFORMATION TECHNOLOGY & ELECTRONIC ENGINEERING, 2017, 18 (09) : 1336 - 1347