返回
Explainability in AI-based behavioral malware detection systems
DOI:10.1016/j.cose.2024.103842.png)
摘要
En 中文
Nowadays, our security and privacy are strongly threatened by malware programs which aim to steal our confidential data and make our systems out of service, among other things. While traditional signature -based malware detection methods or statistical analysis have proven to be ineffective and time-consuming, recently data -driven Artificial Intelligence (AI) techniques, i.e. Machine Learning (ML) and Deep Learning (DL) approaches, have been successfully applied leveraging the behavior of malware in terms of API calls, and achieving promising performances. However, their black -box behavior leads to a lack of explainability thus preventing their application in real world scenarios. In light of this, eXplainable Artificial Intelligence (XAI) methodologies and tools can be effectively embedded within an AI -based malware detection process in order to make more understandable the produced results. In this paper, we propose a XAI framework for behavioral malware detection problems and evaluate the usefulness of four XAI methods (SHAP, LIME, LRP and Attention mechanism) on three datasets with different size, sequence length and number of classes, by which we could evaluate the strengths and weaknesses - from effectiveness and efficiency point of views - of recurrent deep architectures (i.e. Long -Short Term Memory (LSTM) and Gated Recurrent Unit (GRU) models), and their applicability in the modern Cyber Security (CS) scenarios.
Keyword:
Behavioral malware detection
EXplainable artificial intelligence
Data-driven cyber security
Long-short term memory
AI总结
对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。
期刊
C
IF:
5.4
论文数:
4.6K
被引数:
1.4W
机构
引用论文
Cyber Threat Intelligence Mining for Proactive Cybersecurity Defense: A Survey and New Perspectives用于主动网络安全防御的网络威胁情报挖掘: 调查和新观点
An Enhanced Stacked LSTM Method With No Random Initialization for Malware Threat Hunting in Safety and Time-Critical Systems一种增强的无随机初始化的堆叠LSTM方法,用于安全和时间关键系统中的恶意软件威胁搜索
A novel deep framework for dynamic malware detection based on API sequence intrinsic features一种基于API序列内在特征的深度动态恶意软件检测框架
COMPUTERS & SECURITY
IF5.4
A Systematical and longitudinal study of evasive behaviors in windows malware
COMPUTERS & SECURITY
IF5.4

