Malicious Code Detection Using Active Learning

被引:0
|
作者
Moskovitch, Robert [1 ]
Nissim, Nir [1 ]
Elovici, Yuval [1 ]
机构
[1] Ben Gurion Univ Negev, Deutsch Telekom Labs, IL-84105 Beer Sheva, Israel
来源
关键词
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The recent growth in network usage has motivated the creation of new malicious code for various purposes, including economic and other malicious purposes. Currently, dozens of new malicious codes are created every day and this number is expected to increase in the coining years. Today's signature-based anti-viruses and heuristic-based methods are accurate, but cannot detect new malicious code. Recently, classification algorithms were used successfully for the detection of malicious code. We present a complete methodology for the detection of unknown malicious code, inspired by text categorization concepts. However, this approach can be exploited further to achieve a more accurate and efficient acquisition method of unknown malicious files. We use an Active-Learning framework that enables the selection of the unknown files for fast acquisition. We performed ail extensive evaluation of a test collection consisting of more than 30,000 files. We present a rigorous evaluation setup, consisting of real-life scenarios, in which the malicious file content is expected to be low, at about 10% of the files in the stream. We define specific evaluation measures based oil the known precision and recall measures, which show the accuracy of the acquisition process and the improvement in the classifier resulting from the efficient acquisition process.
引用
收藏
页码:74 / 91
页数:18
相关论文
共 50 条
  • [31] Active Malicious Accounts Detection with Multimodal Fusion Machine Learning Algorithm
    Tang, Yuting
    Zhang, Dafang
    Liang, Wei
    Li, Kuan-Ching
    Sukhija, Nitin
    [J]. UBIQUITOUS SECURITY, 2022, 1557 : 38 - 52
  • [32] Detection technology of malicious code based on semantic
    Lu, Qingmei
    Wang, Yulin
    [J]. MULTIMEDIA TOOLS AND APPLICATIONS, 2017, 76 (19) : 19543 - 19555
  • [33] THE BEHAVIOR ORIENTED DETECTION OF MALICIOUS CODE OVERVIEW
    Deng, Jin-Cheng
    Liu, Dan
    Hu, Yue
    Liang, Zong-Wen
    [J]. 2012 INTERNATIONAL CONFERENCE ON WAVELET ACTIVE MEDIA TECHNOLOGY AND INFORMATION PROCESSING (LCWAMTIP), 2012, : 235 - 238
  • [34] Unknown Malicious Code Detection - Practical Issues
    Moskovitch, Robert
    Elovici, Yuval
    [J]. PROCEEDINGS OF THE 7TH EUROPEAN CONFERENCE ON INFORMATION WARFARE AND SECURITY, 2008, : 145 - 152
  • [35] An ensemble framework for interpretable malicious code detection
    Cheng, Jieren
    Zheng, Jiachen
    Yu, Xiaomei
    [J]. INTERNATIONAL JOURNAL OF INTELLIGENT SYSTEMS, 2022, 37 (12) : 10100 - 10117
  • [36] Malicious Code Detection Based on Software Fingerprint
    Yin, Zhimin
    Yu, Xiangzhan
    Niu, Linhua
    [J]. PROCEEDINGS OF THE 2013 THE INTERNATIONAL CONFERENCE ON ARTIFICIAL INTELLIGENCE AND SOFTWARE ENGINEERING (ICAISE 2013), 2013, 37 : 212 - 216
  • [37] Malicious XSS Code Detection with Decision Tree
    Kasim, Omer
    [J]. JOURNAL OF POLYTECHNIC-POLITEKNIK DERGISI, 2020, 23 (01): : 67 - 72
  • [38] ANALYSIS OF RESNET MODEL FOR MALICIOUS CODE DETECTION
    Khan, Riaz Ullah
    Zhang, Xiaosong
    Kumar, Rajesh
    Tariq, Hussain Ahmad
    [J]. 2017 14TH INTERNATIONAL COMPUTER CONFERENCE ON WAVELET ACTIVE MEDIA TECHNOLOGY AND INFORMATION PROCESSING (ICCWAMTIP), 2017, : 239 - 242
  • [39] Detection technology of malicious code based on semantic
    Qingmei Lu
    Yulin Wang
    [J]. Multimedia Tools and Applications, 2017, 76 : 19543 - 19555
  • [40] Detection of Obfuscated Malicious Java']JavaScript Code
    Alazab, Ammar
    Khraisat, Ansam
    Alazab, Moutaz
    Singh, Sarabjot
    [J]. FUTURE INTERNET, 2022, 14 (08):