arrow
返回

Efficient feature extraction methodologies for unknown MP4-Malware detection using Machine learning algorithms

delete2023-06-01
delete1
PRE
AI
A
Aviad Cohen
N
Nir Nissim *
DOI:10.1016/j.eswa.2023.119615delete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
We are living in an era in which daily interaction between individuals and businesses involves sending, uploading, and sharing videos as a means of communication and advertising. However, many users are unaware of the risks associated with opening a malicious video file, it is thus no surprise that cyber-criminals have taken advantage of this situation and adopted this attack vector in recent years. MP4 is one of the most commonly used video formats, and its properties make it well-suited for software vulnerability exploitation across multiple platforms, which can ultimately lead to a cyberattack. Due to their deterministic, signature-based technique, antivirus software solutions are limited in their ability to detect unknown malware, let alone zero-day attacks. Machine learning (ML) algorithms have been effective in detecting known and unknown malware across various file formats, domains, and platforms. ML algorithms' performance relies heavily on the feature extraction methodology. However, to the best of our knowledge, there is no designated and specialized feature extraction methodology for MP4 files which generates a set of features for the task of unknown MP4 file malware detection. In this paper, we present three innovative and efficient feature extraction methodologies for unknown MP4 file malware detection. Two of them are file structure-based and one is knowledge-based. The methodologies are evaluated in a series of five experiments using six ML algorithms and 177 different datasets which represent different configurations of feature extraction, representation, and selection. The datasets are based on a repre-sentative collection of 6,229 files -5,066 benign (-81.3 %) files and 1,163 malicious files (-18.7 %). The first three experiments demonstrate the methodologies' discrimination and generalization capabilities across multiple configurations, in terms of known and unknown MP4 file malware detection. The fourth experiment shows that applying principal component analysis (PCA) on the features suggested by the methodologies can improve time and space complexity and feature resilience while maintaining strong detection and generalization capabilities. In the fifth experiment, the methodologies' best performing configuration is compared to state-of-the-art, generic feature extraction methodologies, such as n-grams, MinHash, and representation and transfer learning (using a CNN), in the task of unknown MP4 file malware detection. The results show that our best performing configu-ration outperforms all other state-of-the-art feature extraction methodologies with an AUC, TPR, and FPR of 0.9951, 0.976, and 0.0 respectively.
Keyword:
Feature Extraction
MP4
Media
Non-Executable
Malware
Detection
Machine Learning

期刊

Expert Systems with Applications 封面图
Expert Systems with Applications
IF:
7.5
论文数:
3.0W
被引数:
10.2W

机构

B
ben gurion university
学者数:
1.3W
论文数: 1.0W
被引数: 5
引用论文

引用论文

RHCE*ceTI encodes partial c and partial e and is often in cis to RHD*DIVa
err2012-07-13
err0
errOAAI
errConnie M. Westhoff; Sunitha Vege; Christine Halter Hipsky; Kim Hue‐Roye; Tamara Copeland; Randall W. Velliquette; Trina Horn; Christine Lomas‐Francis; Marion E. Reid
err分享
err收藏
Repurposed biological scaffolds: kidney to pancreas
err2015-08-07
err0
errOAAI
errBradley J Willenberg; Jose Oca-Cossio; Yunqing Cai; Alicia R Brown; William L Clapp; Dale R Abrahamson; Naohiro Terada; Gary W Ellison; Clayton E Mathews; Christopher D Batich; Edward A Ross
err分享
err收藏
err分享
err收藏
学者 查看更多内容