A Behavior-Based Approach for Malware Detection

A Behavior-Based Approach for Malware Detection
复制标题

DOI:
10.1007/978-3-319-67208-3_11
复制
发表时间:
2017-01
期刊:
--
影响因子:
--
通讯作者:
Rayan Mosli;Rui Li;Bo Yuan;Yin Pan
Rayan Mosli;Rui Li;Bo Yuan;Yin Pan
中科院分区:
其他
文献类型:
--
作者:
Rayan Mosli;Rui Li;Bo Yuan;Yin Pan

文献摘要

被引文献

相似文献

恶意软件是对信息技术系统增长最快的威胁。虽然不可能有一个单一的绝对解决方案来击败恶意软件,但针对恶意软件的堆栈武器库增强了维护安全和隐私的能力。这项研究试图通过研究软件常见的行为活动-使用句柄来加强反恶意软件库。良性和恶意软件的句柄使用的特征被提取和利用,以区分这两个类。提出了一种利用内存取证、信息检索和机器学习技术的自动化恶意软件检测机制。对恶意软件数据集的实验产生了91.4%的恶意软件检测率,准确率和召回率分别为89.8%和91.1%。
Malware is the fastest growing threat to information technology systems. Although a single absolute solution for defeating malware is improbable, a stacked arsenal against malicious software enhances the ability to maintain security and privacy. This research attempts to reinforce the anti-malware arsenal by studying a behavioral activity common to software – the use of handles. The characteristics of handle usage by benign and malicious software are extracted and exploited in an effort to distinguish between the two classes. An automated malware detection mechanism is presented that utilizes memory forensics, information retrieval and machine learning techniques. Experimentation with a malware dataset yields a malware detection rate of 91.4% with precision and recall of 89.8% and 91.1%, respectively.