arrow
返回

Windows malware detection based on static analysis with multiple features

delete2023-04-21
delete4
delete
OA
AI
M
Muhammad Irfan Yousuf *
I
Izza Anwer
A
Ayesha Riasat
K
Khawaja Tahir Zia
S
Suhyun Kim
DOI:10.7717/peerj-cs.1319delete
delete原文链接
delete分享
delete收藏
查看原文
摘要

摘要

En 中文
Malware or malicious software is an intrusive software that infects or performs harmful activities on a computer under attack. Malware has been a threat to individuals and organizations since the dawn of computers and the research community has been struggling to develop efficient methods to detect malware. In this work, we present a static malware detection system to detect Portable Executable (PE) malware in Windows environment and classify them as benign or malware with high accuracy. First, we collect a total of 27,920 Windows PE malware samples divided into six categories and create a new dataset by extracting four types of information including the list of imported DLLs and API functions called by these samples, values of 52 attributes from PE Header and 100 attributes of PE Section. We also amalgamate this information to create two integrated feature sets. Second, we apply seven machine learning models; gradient boosting, decision tree, random forest, support vector machine, K-nearest neighbor, naive Bayes, and nearest centroid, and three ensemble learning techniques including Majority Voting, Stack Generalization, and AdaBoost to classify the malware. Third, to further improve the performance of our malware detection system, we also deploy two dimensionality reduction techniques: Information Gain and Principal Component Analysis. We perform a number of experiments to test the performance and robustness of our system on both raw and selected features and show its supremacy over previous studies. By combining machine learning, ensemble learning and dimensionality reduction techniques, we construct a static malware detection system which achieves a detection rate of 99.5% and error rate of only 0.47%.
Keyword:
Static malware analysis
Windows PE
Machine learning
Multiple features
AI总结

AI总结

对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。

期刊

PeerJ Computer Science 封面图
PeerJ Computer Science
IF:
2.5
论文数:
3.4K
被引数:
6.9K

机构

K
korea institute of science & technology (kist)
学者数:
1.2W
论文数: 1.3W
被引数: 23
U
university of engineering & technology lahore
学者数:
2.7K
论文数: 2.2K
被引数: 0
引用论文

引用论文

A Guide to Preclinical Models of Zoster-Associated Pain and Postherpetic Neuralgia
err2021-09-16
err0
PREAI
errBenjamin E. Warner; William F. Goins; Phillip R. Kramer; Paul R. Kinchington
err分享
err收藏
Association between breastfeeding, host genetic factors, and calicivirus gastroenteritis in a Nicaraguan birth cohort
err
IF0
err2022-04-17
err0
errOAAI
errNadja A. Vielot; Ruthly François; Fredman González; Yaoska Reyes; Emilya Huseynova; Lester Gutierrez; Johan Nordgren; Christian Toval-Ruiz; Samuel Vilchez; Jan Vinjé; Sylvia Becker-Dreps; Filemon Bucardo
err分享
err收藏
Deep learning based Sequential model for malware analysis using Windows exe API Calls
err2020-07-27
err88
errOAAI
errCatak, Ferhat Ozgur; Yaz, Ahmet Faruk; Elezaj, Ogerta; Ahmed, Javed
err分享
err收藏
Expression of IDO1 and PD-L2 in Patients with Benign Lymphadenopathies and Association with Autoimmune Diseases
err2023-01-27
err0
errOAAI
errMaysaa Abdulla; Christer Sundström; Cecilia Lindskog; Peter Hollander
err分享
err收藏
Comparative Analysis of Low-Dimensional Features and Tree-Based Ensembles for Malware Detection Systems
err2020-01-01
err32
errOAAI
errEuh, Seoungyul; Lee, Hyunjong; Kim, Donghoon; Hwang, Doosung
err分享
err收藏
The RAG2 C terminus suppresses genomic instability and lymphomagenesis
err2011-03-02
err0
errOAAI
errLudovic Deriano; Julie Chaumeil; Marc Coussens; Asha Multani; YiFan Chou; Alexander V. Alekseyenko; Sandy Chang; Jane A. Skok; David B. Roth
err分享
err收藏
err分享
err收藏
学者 查看更多内容