arrow
Return

MalInsight: A systematic profiling based malware detection framework

delete2019-01-01
delete64
delete
OA
AI
W
Weijie Han
J
Jingfeng Xue
王
王永 (Yong Wang) *
Z
Zhenyan Liu
Z
Zixiao Kong
DOI:10.1016/j.jnca.2018.10.022delete
deleteOriginal
deleteShare
deleteSave
View PDF
Abstract

Abstract

En 中文
To handle the security threat faced by the widespread use of Internet of Things (IoT) devices due to the ever-lasting increase of malware, the security researchers increasingly rely on machine learning techniques based on various static and/or dynamic features. Unfortunately, the state of the art detection techniques may fail to identify the malware effectively because the malware is often obfuscated to camouflage its characteristics and thwart the analysis process. In order to identify the disguised malware accurately, a malware detection framework named MalInsight is proposed by profiling malware from three aspects which are basic structure, low-level behavior, and high-level behavior. These aspects reflect the structural features, the underlying operations interacting with the OS, and the operations on the files, the registry, and the network respectively. Based on the above findings, an accurate and rich feature space is built which enables to depict and detect malware more effectively. In order to validate the effectiveness of MalInsight, an extensive experiment is conducted on a real-world malware dataset. Our experimental results show that MalInsight can detect not only obfuscated malware instances with an accuracy of 99.76% but also unseen and new malware with an accuracy of 97.21%. Furthermore, Mallnsight can classify the malware samples into their families with an accuracy of 94.2% outperforming the typical detection approach based on the API sequence as the dynamic behavior features by almost 9%. In addition, the importance of the three aspects is evaluated and sorted quantitatively demonstrating that these aspects play the same effects with the optimal feature set.
Keywords:
Malware detection
Malware classification
Systematic profiling
AI Summary

AI Summary

Key information extracted from the uploaded paper, including a brief overview, abstract, background, key highlights, visual analysis, and future outlook.

Journal

Journal of Network and Computer Applications cover
Journal of Network and Computer Applications
IF:
8
Papers:
3.6K
Citations:
1.1W

Organization

B
beijing institute of technology
Scholars:
5.5W
Papers: 4.0W
Citations: 63
Cited Papers

Cited Papers

A Survey on Malware Detection Using Data Mining Techniques
err2017-06-29
err377
PREAI
errYe, Yanfang; Li, Tao; Adjeroh, Donald; Iyengar, S. Sitharama
errShare
errSave
Classification of malware based on integrated static and dynamic features
err2013-03-01
err190
PREAI
errIslam, Rafiqul; Tian, Ronghua; Batten, Lynn M.; Versteeg, Steve
errShare
errSave
Facial age estimation by using stacked feature composition and selection
err2015-06-02
err18
PREAI
errLi, Ya; Peng, Zhanglin; Liang, Depeng; Chang, Huiyou; Cai, Zhaoquan
errShare
errSave
errShare
errSave
researcher View more