Friend or Foe: Discerning Benign vs Malicious Software and Malware Family

Friend or Foe: Discerning Benign vs Malicious Software and Malware Family
复制标题

DOI:
10.1109/globecom46510.2021.9685415
复制
发表时间:
2021-12
期刊:
2021 IEEE Global Communications Conference (GLOBECOM)
影响因子:
--
通讯作者:
Aaron Walker;Tapadhir Das;R. Shukla;S. Sengupta
Aaron Walker;Tapadhir Das;R. Shukla;S. Sengupta
中科院分区:
其他
文献类型:
--
作者:
Aaron Walker;Tapadhir Das;R. Shukla;S. Sengupta

文献摘要

相似文献

恶意软件仍然是网络安全的最严重威胁之一,仅次于社会工程或缺乏用户安全意识。对于企业环境中的Windows系统尤其如此。随着恶意软件继续发展并阻碍遗留检测和预防机制,需要其他方法来确保安全弹性。机器学习提供了许多机会,通过大数据集的优势更好地打击恶意软件威胁。我们的研究强调了如何利用机器学习快速识别恶意软件威胁,使网络安全专业人员能够学习和适应这些威胁。我们在本文中提出的方法通过分析前3,000个Windows系统API函数调用,提供了一种识别恶意软件系列和功能的有效方法。我们比较了MLP、CNN和支持向量机网络,以确定在准确性和速度方面的最佳性能,并发现MLP在我们的数据集上工作得最好。
Malware remains one of the gravest threats to cybersecurity, second only to social engineering or a lack of user security awareness. This is especially true for Windows systems in enterprise environments. As malware continues to evolve and frustrate legacy detection and prevention mechanisms, additional approaches are necessary to ensure security resilience. Machine learning offers many opportunities to better combat malware threats through the advantage of big datasets. Our research highlights how machine learning can be leveraged to identify malware threats with rapid results, enabling cybersecurity professionals to learn and adapt to these threats. The approach we present in this paper produces an efficient methodology to discern malware family and function through analysis of just the first 3,000 Windows system API function calls. We compare MLP, CNN, and SVM networks to determine the best performance in terms of accuracy and speed and find that MLP works the best with our dataset.