arrow
返回

A cost analysis of machine learning using dynamic runtime opcodes for malware detection

delete2019-08-01
delete15
delete
OA
AI
D
Domhnall Carlin *
P
Philip O’Kane
S
Sakir Sezer
DOI:10.1016/j.cose.2019.04.018delete
delete原文链接
delete分享
delete收藏
查看原文
摘要

摘要

En 中文
The ongoing battle between malware distributors and those seeking to prevent the onslaught of malicious code has, so far, favored the former. Anti-virus methods are faltering with the rapid evolution and distribution of new malware, with obfuscation and detection evasion techniques exacerbating the issue. Recent research has monitored low-level opcodes to detect malware. Such dynamic analysis reveals the code at runtime, allowing the true behaviour to be examined. While previous research uses machine learning techniques to accurately detect malware using dynamic runtime opcodes, underpinning datasets have been poorly sampled and inadequate in size. Further, the datasets are always fixed size and no attempt, to our knowledge, has been made to examine the cost of retraining malware classification models on datasets which grow continually. In the literature, researchers discuss the explosion of malware, yet opcode analyses have used fixed-size datasets, with no deference to how this model will cope with retraining on escalating datasets. The research presented here examines this problem, and makes several novel contributions to the current body of knowledge. First, the performance of 23 machine learning algorithms are investigated with respect to the largest run trace dataset in the literature. Second, following an extensive hyperparameter selection process, the performance of each classifier is compared, on both accuracy and computational costs (CPU time). Lastly, the cost of retraining and testing updatable and non-updatable classifiers, both parallelized and non-parallelized, is examined with simulated escalating datasets. This provides insight into how implemented malware classifiers would perform, given simulated dataset escalation. We find that parallelized RandomForest, using 4 cores, provides the optimal performance, with high accuracy and low training and testing times. (C) 2019 Elsevier Ltd. All rights reserved.
Keyword:
Malicious code
Network security
Machine learning
Computer security
Malware
AI总结

AI总结

对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。

期刊

C
Computers and Security
IF:
5.4
论文数:
4.6K
被引数:
1.4W

机构

Q
Queen's University Belfast
学者数:
1.6W
论文数: 1.7W
被引数: 2.5W
引用论文

引用论文

Multifrequency EPR Study of Metallofullerenes:  Eu@C82 and Eu@C74
err2004-08-20
err0
PREAI
errHideto Matsuoka; Norio Ozawa; Takeshi Kodama; Hiroyuki Nishikawa; Isao Ikemoto; Koichi Kikuchi; Ko Furukawa; Kazunobu Sato; Daisuke Shiomi; Takeji Takui; Tatsuhisa Kato
err分享
err收藏
AusArray: quality passive seismic data to underpin updatable national velocity models of the lithosphere
err
IF0
err2020-01-01
err0
PREAI
errA. Gorbatov; K. Czarnota; B. Hejrani; M. Haynes; R. Hassan; A. Medlin; J. Zhao; F. Zhang; M. Salmon; H. Tkalčić; H. Yuan; M. Dentith; N. Rawlinson; A.M. Reading; B.L.N. Kennett; C. Bugden; M. Costello
err分享
err收藏
Bagging predictorsBagging预测器
err1996-08-01
err1.0W
PREAI
errBreiman, L
err分享
err收藏
Logistic model trees逻辑模型树
err2005-05-01
err943
errOAAI
errLandwehr, N; Hall, M; Frank, E
err分享
err收藏
Expanding access to primary healthcare for women through a microfinance institution: A case study from rural Guatemala
err2018-12-01
err0
PREAI
errMarcela Colom; Kirsten Austad; Neftali Sacuj; Karen Larson; Peter Rohloff
err分享
err收藏
Allosteric Regulation in Phosphofructokinase from the Extreme Thermophile Thermus thermophilus
err2013-12-27
err0
errOAAI
errMaria S. McGresham; Michelle Lovingshimer; Gregory D. Reinhart
err分享
err收藏
学者 查看更多内容