返回
SMASH: A Malware Detection Method Based on Multi-Feature Ensemble Learning
DOI:10.1109/ACCESS.2019.2934012.png)
摘要
En 中文
With the increasing variants of malware, it is of great significance to detect malware and ensure system security effectively. The existing malware dynamic detection methods are vulnerable to evasion attacks. For this situation, we propose a malware dynamic detection method based on mufti-feature ensemble learning. Firstly, the method adopts the combination of software features such as API call sequence with high detection precision and low-level hardware features such as resistance to evasion the memory dump grayscale and hardware performance counters. Secondly, we improve each feature based on the original research. We select a more advanced classifier model to improve the detection precision of a single feature. Finally, an ensemble learning algorithm composed of multiple classification algorithms detects malware, the multi-features can describe malware behavior from multi-dimensions to improve detection performance. We use a large number of malware sample dataset to experiment, and the results show that our detection method can obtain good detection precision rate, and is better than other recently proposed dynamic detection methods in anti-evasion performance.
Keyword:
Anti-evasion
dynamic detection
hardware features
memory dump
AI总结
对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。
期刊
IF:
3.6
论文数:
9.8W
被引数:
29.4W
机构
引用论文
A malware detection method based on family behavior graph一种基于家族行为图的恶意软件检测方法
COMPUTERS & SECURITY
IF5.4
MADAM: Effective and Efficient Behavior-based Android Malware Detection and PreventionMADAM: 有效和高效的基于行为的Android恶意软件检测和预防

