arrow
返回

Malware classification using self organising feature maps and machine activity data

delete2018-03-01
delete86
delete
OA
AI
P
Pete Burnap *
R
Richard French
F
Frederick Turner
K
Kevin Jones
DOI:10.1016/j.cose.2017.11.016delete
delete原文链接
delete分享
delete收藏
查看原文
摘要

摘要

En 中文
In this article we use machine activity metrics to automatically distinguish between malicious and trusted portable executable software samples. The motivation stems from the growth of cyber attacks using techniques that have been employed to surreptitiously deploy Advanced Persistent Threats (APTs). APTs are becoming more sophisticated and able to obfuscate much of their identifiable features through encryption, custom code bases and in memory execution. Our hypothesis is that we can produce a high degree of accuracy in distinguishing malicious from trusted samples using Machine Learning with features derived from the inescapable footprint left behind on a computer system during execution. This includes CPU, RAM, Swap use and network traffic at a count level of bytes and packets. These features are continuous and allow us to be more flexible with the classification of samples than discrete features such as API calls (which can also be obfuscated) that form the main feature of the extant literature. We use these continuous data and develop a novel classification method using Self Organizing Feature Maps to reduce over fitting during training through the ability to create unsupervised clusters of similar behaviour that are subsequently used as features for classification, rather than using the raw data. We compare our method to a set of machine classification methods that have been applied in previous research and demonstrate an increase of between 7.24% and 25.68% in classification accuracy using our method and an unseen dataset over the range of other machine classification methods that have been applied in previous research. (C) 2017 The Authors. Published by Elsevier Ltd.
Keyword:
Malware
Machine learning
Self organising maps
Intrusion detection
Data science
Security operation centre
AI总结

AI总结

对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。

期刊

C
Computers and Security
IF:
5.4
论文数:
4.6K
被引数:
1.4W

机构

C
Cardiff University
学者数:
2.7W
论文数: 2.5W
被引数: 3.5W
引用论文

引用论文

Radiologic assessment of the early postoperative total‐laryngectomy patient
err2009-01-04
err0
errOAAI
errBrett L. Moses; David W. Eisele; Bronwyn Jones
err分享
err收藏
Gender ratio in dyslexia阅读障碍的性别比例
err1998-12-01
err0
PREAI
errT. R. Miles; M. N. Haslum; T. J. Wheeler
err分享
err收藏
Essentials of the self-organizing map
err2013-01-01
err1.1K
PREAI
errKohonen, Teuvo
err分享
err收藏
err分享
err收藏
Intrasexual competition and sexual selection in cooperative mammals
err2006-12-01
err0
PREAI
errT. H. Clutton-Brock; S. J. Hodge; G. Spong; A. F. Russell; N. R. Jordan; N. C. Bennett; L. L. Sharpe; M. B. Manser
err分享
err收藏
err分享
err收藏
没有更多内容