Friend or Foe: Discerning Benign vs Malicious Software and Malware Family
Friend or Foe: Discerning Benign vs Malicious Software and Malware Family
复制标题
DOI:
10.1109/globecom46510.2021.9685415
复制
发表时间:
2021-12
期刊:
影响因子:
--
通讯作者:
Aaron Walker;Tapadhir Das;R. Shukla;S. Sengupta
中科院分区:
文献类型:
--
作者:
Aaron Walker;Tapadhir Das;R. Shukla;S. Sengupta
Malware remains one of the gravest threats to cybersecurity, second only to social engineering or a lack of user security awareness. This is especially true for Windows systems in enterprise environments. As malware continues to evolve and frustrate legacy detection and prevention mechanisms, additional approaches are necessary to ensure security resilience. Machine learning offers many opportunities to better combat malware threats through the advantage of big datasets. Our research highlights how machine learning can be leveraged to identify malware threats with rapid results, enabling cybersecurity professionals to learn and adapt to these threats. The approach we present in this paper produces an efficient methodology to discern malware family and function through analysis of just the first 3,000 Windows system API function calls. We compare MLP, CNN, and SVM networks to determine the best performance in terms of accuracy and speed and find that MLP works the best with our dataset.