arrow
Return

Multiple instance learning for malware classification

delete2018-03-01
delete45
PRE
AI
J
Jan Stiborek *
T
Tomáš Pevný
M
Martin Řehák
DOI:10.1016/j.eswa.2017.10.036delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
This work addresses classification of unknown binaries executed in sandbox by modeling their interaction with system resources (files, mutexes, registry keys and communication with servers over the network) and error messages provided by the operating system, using vocabulary-based method from the multiple instance learning paradigm. It introduces similarities suitable for individual resource types that combined with an approximative clustering method efficiently group the system resources and define features directly from data. This approach effectively removes randomization often employed by malware authors and projects samples into low-dimensional feature space suitable for common classifiers. An extensive comparison to the state of the art on a large corpus of binaries demonstrates that the proposed solution achieves superior results using only a fraction of training samples. Moreover, it makes use of a source of information different than most of the prior art, which increases the diversity of tools detecting the malware, hence making detection evasion more difficult. (C) 2017 Elsevier Ltd. All rights reserved.
Keywords:
Malware
Dynamic analysis
Sandboxing
Multiple instance learning
Classification
Random forest
AI Summary

AI Summary

Key information extracted from the uploaded paper, including a brief overview, abstract, background, key highlights, visual analysis, and future outlook.

Journal

Expert Systems with Applications cover
Expert Systems with Applications
IF:
7.5
Papers:
2.9W
Citations:
10.2W

Organization

C
cisco systems inc
Scholars:
383
Papers: 354
Citations: 0