arrow
返回

A time-interval-based active learning framework for enhanced PE malware acquisition and detection

delete2022-10-01
delete5
PRE
AI
I
Ido Finder
N
Nir Nissim *
DOI:10.1016/j.cose.2022.102838delete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
Malware increasingly threatens users around the world on a variety of cybernetic platforms, resulting in damages of billions of dollars each year. In recent years, in order to improve the detection capabilities of widely used antivirus (AV) tools, machine learning (ML) algorithms and dynamic malware analysis have been leveraged for the extraction and learning of rich multivariate time-series data (MTSD) associated with behavioral information. Such MTSD can be exploited using a time-interval temporal pattern (TP) mining approach, however this approach has not been widely explored for the task of malware detection. The use of TPs enables the discovery of complex temporal relations between different variables, improves the ability to cope with missing values and noisy data, and provides explainability. In light of the continuous creation of new unknown malware on a daily basis, detection mechanisms require frequent updating to keep pace with the changing reality. Active learning (AL) can address the updatability gap by efficiently selecting and acquiring a small yet informative set of new samples while reducing the labeling efforts of experts; AL also provides maximal improvement of machine-learning-based detection models, which can further contribute to the updatability of antimalware tools. However, the use of AL methods for the acquisition of time-interval TP-based samples has yet to be explored. In this paper, we present novel AL methods and a detection framework for improved malware detection based on dynamic analysis, time-interval TPs, and ML algorithms. The proposed framework is capable of both prioritizing the acquisition of malicious samples and improving the malware detection capabilities of ML classifiers and antimalware tools. Our proposed framework was evaluated in an extensive set of experiments on a comprehensive data collection of 9,328 portable executables (5,00 0 benign and 4,328 malicious) that were executed in the Windows 10 environment. The results demonstrated our AL methods' ability to prioritize the acquisition of malware and managed to acquire up to 93.5% of the malicious files each day, allowing frequent updating of antimalware tools. In addition, our framework was shown to be effective in improving the detection capabilities of several ML classifiers over time, with the best results (AUC of 95.15%) achieved by the SVM classifier. Our framework also showed that TPs can be used to identify emerging trends in malicious behavior. (C) 2022 Elsevier Ltd. All rights reserved.
Keyword:
Active learning
Time-series
Malware
Detection
Dynamic analysis

期刊

C
Computers and Security
IF:
5.4
论文数:
4.6K
被引数:
1.4W

机构

B
ben gurion university
学者数:
1.3W
论文数: 1.0W
被引数: 5
引用论文

引用论文

err
IF0
err
err0
PREAI
err
err分享
err收藏
A Survey on Malware Detection Using Data Mining Techniques
err2017-06-29
err377
PREAI
errYe, Yanfang; Li, Tao; Adjeroh, Donald; Iyengar, S. Sitharama
err分享
err收藏
Sec-Lib: Protecting Scholarly Digital Libraries From Infected Papers Using Active Machine Learning Framework
err2019-01-01
err8
errOAAI
errNissim, Nir; Cohen, Aviad; Wu, Jian; Lanzi, Andrea; Rokach, Lior; Elovici, Yuval; Giles, Lee
err分享
err收藏
err分享
err收藏
Detecting Cryptomining Malware: a Deep Learning Approach for Static and Dynamic Analysis
err2020-01-21
err66
PREAI
errDarabian, Hamid; Homayounoot, Sajad; Dehghantanha, Ali; Hashemi, Sattar; Karimipour, Hadis; Parizi, Reza M.; Choo, Kim-Kwang Raymond
err分享
err收藏
Robust active learning for the diagnosis of parasites
err2015-11-01
err32
PREAI
errSaito, Priscila T. M.; Suzuki, Celso T. N.; Gomes, Jancarlo F.; de Rezende, Pedro J.; Falcao, Alexandre X.
err分享
err收藏
学者 查看更多内容