A novel machine learning approach for detecting first-time-appeared malware

计算机科学 恶意软件 人工智能 机器学习 计算机安全
作者
Kamran Shaukat,Suhuai Luo,Vijay Varadharajan
出处
期刊:Engineering Applications of Artificial Intelligence [Elsevier BV]
卷期号:131: 107801-107801 被引量:38
标识
DOI:10.1016/j.engappai.2023.107801
摘要

Conventional malware detection approaches have the overhead of feature extraction, the requirement of domain experts, and are time-consuming and resource-intensive. Learning-based approaches are the mainstay of malware detection as they overcome most of these challenges by significantly improving the detection effectiveness and providing a low false positive rate. The exponential growth of malware variants and first-time-appeared malware, which includes polymorphic and zero-day attacks, are some of the significant challenges to learning-based malware detectors. These challenges have catastrophic impacts on the detection effectiveness of these learning-based malware detectors. This paper proposes a novel deep learning-based framework to detect first-time-appeared malware effectively and efficiently by providing better performance than conventional malware detection approaches. First, it translates and visualises each Windows portable executable (PE) file into a coloured image to eliminate the overhead of feature extraction and the need for domain experts to analyse the features. In the subsequent step, a fine-tuned deep learning model is used to extract the deep features from the last fully connected layer. The step has reduced the cost of training required by the deep learning models if used for end-to-end classification. The third step selects the most important and influential features through a powerful feature selection algorithm. The most important features are then fed to a one-class classifier for final detection. With the one-class classifier, an enclosed boundary around the features of benign data is constructed. Anything outside the boundary is declared as an anomaly/malicious. It has enhanced the framework's ability to detect evolving, unseen, polymorphic, and zero-day attacks, as well as reducing the problem of overfitting. The detection effectiveness of the proposed framework is validated with state-of-the-art deep learning models and conventional approaches. The proposed framework has outperformed with an accuracy of 99.30% on the Malimg dataset. The Wilcoxon signed-rank test is used to validate the statistical significance of the proposed framework. It is evident from the results that the proposed framework is effective and can be used in the defence industry, resulting in more powerful and robust solutions against zero-day and polymorphic attacks.
最长约 10秒,即可获得该文献文件

科研通智能强力驱动
Strongly Powered by AbleSci AI
科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
陈文学完成签到,获得积分10
刚刚
cdercder应助长度2到采纳,获得10
1秒前
1秒前
少双完成签到,获得积分10
1秒前
1秒前
无花果应助hZC采纳,获得10
1秒前
wanci应助许安采纳,获得10
1秒前
冰晨发布了新的文献求助10
1秒前
调皮静竹发布了新的文献求助10
1秒前
1秒前
2秒前
2秒前
小马甲应助爆爆采纳,获得10
2秒前
2秒前
玩命的书琴完成签到,获得积分10
2秒前
疲倦之躯发布了新的文献求助10
2秒前
行走的荷尔蒙应助Elias采纳,获得60
2秒前
lulu完成签到,获得积分20
3秒前
3秒前
诺姗姗发布了新的文献求助10
3秒前
3秒前
科研通AI6.4应助拼搏一曲采纳,获得10
4秒前
4秒前
ZHOUZHEN完成签到,获得积分10
4秒前
珈心果发布了新的文献求助10
4秒前
loeyyu完成签到,获得积分10
5秒前
杂粮米发布了新的文献求助10
5秒前
拳拳完成签到 ,获得积分10
5秒前
5秒前
炙热幻灵完成签到,获得积分10
6秒前
6秒前
6秒前
6秒前
在水一方应助lyn2002采纳,获得10
6秒前
复杂易巧发布了新的文献求助10
6秒前
脑洞疼应助lanshuitai采纳,获得10
7秒前
liuxinyu发布了新的文献求助10
7秒前
落后的柜子完成签到,获得积分10
7秒前
7秒前
小郭同学完成签到,获得积分10
7秒前
高分求助中
(应助此贴封号)【重要!!请各用户(尤其是新用户)详细阅读】【科研通的精品贴汇总】 10000
Principles of town planning: translating concepts to applications 1000
Navigating Normative Orders. Interdisciplinary Perspectives 800
1 Peter and Christ's Descent to the Dead in Its Early Christian Reception 700
Organizational Behavior 510
Management and the Arts 510
Matrix Methods in Data Mining and Pattern Recognition Second Edition 510
热门求助领域 (近24小时)
化学 材料科学 医学 生物 纳米技术 工程类 有机化学 化学工程 生物化学 计算机科学 内科学 物理 复合材料 催化作用 细胞生物学 无机化学 光电子学 物理化学 电极 基因
热门帖子
关注 科研通微信公众号,转发送积分 7739777
求助须知:如何正确求助?哪些是违规求助? 9288621
关于积分的说明 20190926
捐赠科研通 7317946
什么是DOI,文献DOI怎么找? 3306213
关于科研通互助平台的介绍 2458630
邀请新用户注册赠送积分活动 2316249