FindMal: A file-to-file social network based malware detection framework
FindMal: A file-to-file social network based malware detection framework
复制标题
DOI:
10.1016/j.knosys.2016.09.004
复制
发表时间:
2016-11
期刊:
影响因子:
--
通讯作者:
Ming Ni;Tao Li;Qianmu Li;Hong Zhang;Yanfang Ye
中科院分区:
文献类型:
--
作者:
Ming Ni;Tao Li;Qianmu Li;Hong Zhang;Yanfang Ye
The rapid development of malicious software programs has posed severe threats to Computer and Internet security. Therefore, it motivates anti-malware vendors and researchers to develop novel methods which are capable of protecting users against new threats. Existing malware detectors mostly treat the file samples separately using supervised learning algorithms. However, ignoring the relationship among file samples limits the capability of malware detectors. In this paper, based on the file-to-file social network, we present a new malware detection framework, FindMal(File-to-File SocialNetwork basedMalware Detection Framework), including graph-based features extraction, Label Propagation algorithm, and active learning strategy. Nearest neighbors are first chosen as adjacent nodes for each file node to constructkNN file relation graph. Three file relation graph features are proposed to sample the representative file samples for labeling. Then, Label Propagation algorithm, which propagates the label information from labeled file samples to unlabeled files, is applied to learn the probability that one unknown file is classified as malicious or benign. A batch mode active learning method is employed to reduce the labeling cost and improve the performance of Label Propagation. Comprehensive experiments on real and large scale dataset obtained from an anti-malware company are performed. The results demonstrate that our proposed FindMal outperforms other existing detection models in classifying file samples.