A Behavior-Based Approach for Malware Detection
A Behavior-Based Approach for Malware Detection
复制标题
DOI:
10.1007/978-3-319-67208-3_11
复制
发表时间:
2017-01
期刊:
影响因子:
--
通讯作者:
Rayan Mosli;Rui Li;Bo Yuan;Yin Pan
中科院分区:
文献类型:
--
作者:
Rayan Mosli;Rui Li;Bo Yuan;Yin Pan
Malware is the fastest growing threat to information technology systems. Although a single absolute solution for defeating malware is improbable, a stacked arsenal against malicious software enhances the ability to maintain security and privacy. This research attempts to reinforce the anti-malware arsenal by studying a behavioral activity common to software – the use of handles. The characteristics of handle usage by benign and malicious software are extracted and exploited in an effort to distinguish between the two classes. An automated malware detection mechanism is presented that utilizes memory forensics, information retrieval and machine learning techniques. Experimentation with a malware dataset yields a malware detection rate of 91.4% with precision and recall of 89.8% and 91.1%, respectively.