arrow
返回

Feature analysis for data-driven APT-related malware discrimination

delete2021-05-01
delete12
PRE
AI
L
Luis Francisco Martín Liras *
A
Adolfo Rodríguez de Soto
M
Miguel A. Prada
DOI:10.1016/j.cose.2021.102202delete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
Advanced Persistent Threats (APTs) have become a major concern for IT security professionals around the world. These attacks are characterized by the use of both highly sophisticated, evasive and cautious human and technical resources. It is very common to notice the combined use of different malware in long APT campaigns. This fact makes it interesting to investigate the malware that has been used in APT campaigns. Different approaches have been proposed to find discriminatory features to detect APT malware. Features from either static, dynamic and network-related analyses have been separately proposed for that aim. The new approach considered in this study aims to identify the most discriminatory features to distinguish APT-campaign-belonging malware from non-APT malware executables. This approach suggests to identify the discriminatory features from not one but all three groups of these analyses by using domain knowledge and with a purpose of interpretability. As a result, a set with the most discriminatory features of each type is provided. To achieve this set, well-known machine learning techniques have been used. One of the most important limitations in the use of these learning techniques is the availability of a relevant amount of data. In this paper, a large dataset of 19,457 malware samples is publicly provided, including both malware known to be related with APTs and generic non-APT belonging malware samples. In order to analyze the discrimination ability of the features, the proposed approach follows several steps. First, an exploratory analysis is conducted to obtain knowledge about the data structure. Later, feature selection is performed using different discriminatory techniques. The resulting selection of features is assessed by means of four well-known binary classification techniques. The high accuracy of the results shows that the proposed features are discriminative enough for the stated purpose. Finally, these results are interpreted and the findings are discussed from the perspective of prior knowledge and assumptions about APT-related malware. (c) 2021 Elsevier Ltd. All rights reserved.
Keyword:
Malware
Advanced persistent threat
Machine learning
Exploratory data analysis
Feature analysis
AI总结

AI总结

对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。

期刊

C
Computers and Security
IF:
5.4
论文数:
4.6K
被引数:
1.4W

机构

U
universidad de leon
学者数:
4.9K
论文数: 3.8K
被引数: 3
引用论文

引用论文

Detecting APT Malware Infections Based on Malicious DNS and Traffic Analysis
err2015-01-01
err128
errOAAI
errZhao, Guodong; Xu, Ke; Xu, Lei; Wu, Bo
err分享
err收藏
err分享
err收藏
err分享
err收藏
The Role of Vaccinium Myrtillus in the Prevention of Renal Injury in an Experimental Model of Ruptured Abdominal Aortic Aneurysm
err2020-01-01
err0
errOAAI
errŞaban Ergene; Doğuş Hemşinli; Sedat Ozan Karakişi; Tolga Mercantepe; Levent Tumkaya; Adnan Yilmaz
err分享
err收藏
Support-vector networks支持向量网络
err1995-09-01
err0
errOAAI
errCorinna Cortes; Vladimir Vapnik
err分享
err收藏
学者 查看更多内容