RAMD: registry-based anomaly malware detection using one-class ensemble classifiers

被引:19
|
作者
Tajoddin, Asghar [1 ]
Abadi, Mahdi [1 ]
机构
[1] Tarbiat Modares Univ, Sch Elect & Comp Engn, Tehran, Iran
关键词
Windows malware; Registry-based malware detection; Ensemble classifier; One-class classification; Pruning algorithm; Memetic firefly algorithm; Aggregation operator; Superincreasing ordered weighted averaging; ALGORITHM; SOFTWARE; BEHAVIOR; REGRESSION; MACHINE; ROBUST;
D O I
10.1007/s10489-018-01405-0
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Malware is continuously evolving and becoming more sophisticated to avoid detection. Traditionally, the Windows operating system has been the most popular target for malware writers because of its dominance in the market of desktop operating systems. However, despite a large volume of new Windows malware samples that are collected daily, there is relatively little research focusing on Windows malware. The Windows Registry, or simply the registry, is very heavily used by programs in Windows, making it a good source for detecting malicious behavior. In this paper, we present RAMD, a novel approach that uses an ensemble classifier consisting of multiple one-class classifiers to detect known and especially unknown malware abusing registry keys and values for malicious intent. RAMD builds a model of registry behavior of benign programs and then uses this model to detect malware by looking for anomalous registry accesses. In detail, it constructs an initial ensemble classifier by training multiple one-class classifiers and then applies a novel swarm intelligence pruning algorithm, called memetic firefly-based ensemble classifier pruning (MFECP), on the ensemble classifier to reduce its size by selecting only a subset of one-class classifiers that are highly accurate and have diversity in their outputs. To combine the outputs of one-class classifiers in the pruned ensemble classifier, RAMD uses a specific aggregation operator, called Fibonacci-based superincreasing ordered weighted averaging (FSOWA). The results of our experiments performed on a dataset of benign and malware samples show that RAMD can achieve about 98.52% detection rate, 2.19% false alarm rate, and 98.43% accuracy.
引用
收藏
页码:2641 / 2658
页数:18
相关论文
共 50 条
  • [1] RAMD: registry-based anomaly malware detection using one-class ensemble classifiers
    Asghar Tajoddin
    Mahdi Abadi
    [J]. Applied Intelligence, 2019, 49 : 2641 - 2658
  • [2] Video Anomaly Detection using Ensemble One-class Classifiers
    Li, Gang
    Feng, Zuren
    Lv, Na
    [J]. 2018 37TH CHINESE CONTROL CONFERENCE (CCC), 2018, : 9343 - 9349
  • [3] One-class classifiers ensemble based anomaly detection scheme for process control systems
    Wang, Biao
    Mao, Zhizhong
    [J]. TRANSACTIONS OF THE INSTITUTE OF MEASUREMENT AND CONTROL, 2018, 40 (12) : 3466 - 3476
  • [4] Using an ensemble of one-class SVM classifiers to harden payload-based anomaly detection systems
    Perdisci, Roberto
    Gu, Guofei
    Lee, Wenke
    [J]. ICDM 2006: SIXTH INTERNATIONAL CONFERENCE ON DATA MINING, PROCEEDINGS, 2006, : 488 - 498
  • [5] Adapting an Ensemble of One-Class Classifiers for a Web-Layer Anomaly Detection System
    Kozik, Rafal
    Choras, Michal
    [J]. 2015 10TH INTERNATIONAL CONFERENCE ON P2P, PARALLEL, GRID, CLOUD AND INTERNET COMPUTING (3PGCIC), 2015, : 724 - 729
  • [6] Anomaly detection in computer networks using dissimilarity-based one-class classifiers
    Ma, Jun
    Dai, GuanZhong
    [J]. ISDA 2008: EIGHTH INTERNATIONAL CONFERENCE ON INTELLIGENT SYSTEMS DESIGN AND APPLICATIONS, VOL 2, PROCEEDINGS, 2008, : 14 - 18
  • [7] FENOC: An Ensemble One-Class Learning Framework for Malware Detection
    Liu, Jiachen
    Song, Jianfeng
    Miao, Qiguang
    Cao, Ying
    [J]. 2013 9TH INTERNATIONAL CONFERENCE ON COMPUTATIONAL INTELLIGENCE AND SECURITY (CIS), 2013, : 523 - 527
  • [8] Semi-supervised Gas Detection Using an Ensemble of One-class Classifiers
    Fan, Han
    Bennett, Victor Hernandez
    Schaffernicht, Erik
    Lilienthal, Achim J.
    [J]. 2019 IEEE INTERNATIONAL SYMPOSIUM ON OLFACTION AND ELECTRONIC NOSE (ISOEN 2019), 2019, : 240 - 243
  • [9] Ensemble of One-class Classifiers for Network Intrusion Detection System
    Zainal, Anazida
    Maarof, Mohd Aizaini
    Shamsuddin, Siti Mariyam
    Abraham, Ajith
    [J]. FOURTH INTERNATIONAL SYMPOSIUM ON INFORMATION ASSURANCE AND SECURITY, PROCEEDINGS, 2008, : 180 - +
  • [10] Acoustic Sensor Based Activity Recognition Using Ensemble of One-Class Classifiers
    Tripathi, Achyut Mani
    Baruah, Diganta
    Baruah, Rashmi Dutta
    [J]. 2015 IEEE INTERNATIONAL CONFERENCE ON EVOLVING AND ADAPTIVE INTELLIGENT SYSTEMS (EAIS), 2015,