Combining Supervised and Unsupervised Learning for Zero-Day Malware Detection

被引:0
|
作者
Comar, Prakash Mandayam [1 ]
Liu, Lei [1 ]
Saha, Sabyasachi [2 ]
Tan, Pang-Ning [1 ]
Nucci, Antonio [2 ]
机构
[1] Michigan State Univ, Dept Comp Sci, E Lansing, MI 48824 USA
[2] Narus Inc, Sunnyvale, CA 94085 USA
关键词
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Malware is one of the most damaging security threats facing the Internet today. Despite the burgeoning literature, accurate detection of malware remains an elusive and challenging endeavor due to the increasing usage of payload encryption and sophisticated obfuscation methods. Also, the large variety of malware classes coupled with their rapid proliferation and polymorphic capabilities and imperfections of real-world data (noise, missing values, etc) continue to hinder the use of more sophisticated detection algorithms. This paper presents a novel machine learning based framework to detect known and newly emerging malware at a high precision using layer 3 and layer 4 network traffic features. The framework leverages the accuracy of supervised classification in detecting known classes with the adaptability of unsupervised learning in detecting new classes. It also introduces a tree-based feature transformation to overcome issues due to imperfections of the data and to construct more informative features for the malware detection task. We demonstrate the effectiveness of the framework using real network data from a large Internet service provider.
引用
收藏
页码:2022 / 2030
页数:9
相关论文
共 50 条
  • [41] A framework for zero-day vulnerabilities detection and prioritization
    Singh, Umesh Kumar
    Joshi, Chanchala
    Kanellopoulos, Dimitris
    [J]. JOURNAL OF INFORMATION SECURITY AND APPLICATIONS, 2019, 46 : 164 - 172
  • [42] Detecting Zero-Day Intrusion Attacks Using Semi-Supervised Machine Learning Approaches
    Mbona, Innocent
    Eloff, Jan H. P.
    [J]. IEEE ACCESS, 2022, 10 : 69822 - 69838
  • [43] An unsupervised approach for the detection of zero-day distributed denial of service attacks in Internet of Things networks
    Roopak, Monika
    Parkinson, Simon
    Tian, Gui Yun
    Ran, Yachao
    Khan, Saad
    Chandrasekaran, Balasubramaniyan
    [J]. IET NETWORKS, 2024,
  • [44] Breakthrough to Adaptive and Cost-Aware Hardware-Assisted Zero-Day Malware Detection: A Reinforcement Learning-Based Approach
    He, Zhangying
    Makrani, Hosein Mohammadi
    Rafatirad, Setareh
    Homayoun, Houman
    Sayadi, Hossein
    [J]. 2022 IEEE 40TH INTERNATIONAL CONFERENCE ON COMPUTER DESIGN (ICCD 2022), 2022, : 231 - 238
  • [45] Learning from Limited Heterogeneous Training Data: Meta-Learning for Unsupervised Zero-Day Web Attack Detection across Web Domains
    Li, Peiyang
    Wang, Ye
    Li, Qi
    Liu, Zhuotao
    Xu, Ke
    Ren, Ju
    Liu, Zhiying
    Lin, Ruilin
    [J]. PROCEEDINGS OF THE 2023 ACM SIGSAC CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY, CCS 2023, 2023, : 1020 - 1034
  • [46] Zero-Day Attack Detection using Ensemble Technique
    Wangde, Fawaz, I
    Mulay, Shivam P.
    Adhao, Rahul B.
    Pachghare, Vinod K.
    [J]. INTERNATIONAL JOURNAL OF NEXT-GENERATION COMPUTING, 2021, 12 (05): : 551 - 557
  • [47] Image-Based Zero-Day Malware Detection in IoMT Devices: A Hybrid AI-Enabled Method
    He, Zhangying
    Sayadi, Hossein
    [J]. 2023 24TH INTERNATIONAL SYMPOSIUM ON QUALITY ELECTRONIC DESIGN, ISQED, 2023, : 82 - 89
  • [48] The Zero-Day Salesmen
    Greenberg, Andy
    [J]. FORBES, 2012, 189 (06): : 40 - +
  • [49] Distributed Detection of Zero-Day Network Traffic Flows
    Miao, Yuantian
    Pan, Lei
    Rajasegarar, Sutharshan
    Zhang, Jun
    Leckie, Christopher
    Xiang, Yang
    [J]. DATA MINING, AUSDM 2017, 2018, 845 : 173 - 191
  • [50] Zero-day attack detection: a systematic literature review
    Ahmad, Rasheed
    Alsmadi, Izzat
    Alhamdani, Wasim
    Tawalbeh, Lo'ai
    [J]. ARTIFICIAL INTELLIGENCE REVIEW, 2023, 56 (10) : 10733 - 10811