Performance Comparison of Training Datasets for System Call-Based Malware Detection with Thread Information

被引:3
|
作者
Kajiwara, Yuki [1 ,2 ]
Zheng, Junjun [1 ]
Mouri, Koichi [1 ]
机构
[1] Ritsumeikan Univ, Coll Informat Sci & Engn, Kusatsu 5258577, Japan
[2] NEC Corp Ltd, Tokyo 1088001, Japan
关键词
malware detection; machine learning; system calls; thread;
D O I
10.1587/transinf.2021EDP7067
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The number of malware, including variants and new types, is dramatically increasing over the years, posing one of the greatest cyber-security threats nowadays. To counteract such security threats, it is crucial to detect malware accurately and early enough. The recent advances in machine learning technology have brought increasing interest in malware detection. A number of research studies have been conducted in the field. It is well known that malware detection accuracy largely depends on the training dataset used. Creating a suitable training dataset for efficient malware detection is thus crucial. Different works usually use their own dataset; therefore, a dataset is only effective for one detection method, and strictly comparing several methods using a common training dataset is difficult. In this paper, we focus on how to create a training dataset for efficiently detecting malware. To achieve our goal, the first step is to clarify the information that can accurately characterize malware. This paper concentrates on threads, by treating them as important information for characterizing malware. Specifically, on the basis of the dynamic analysis log from the Alkanet, a system call tracer, we obtain the thread information and classify the thread information processing into four patterns. Then the malware detection is performed using the number of transitions of system calls appearing in the thread as a feature. Our comparative experimental results showed that the primary thread information is important and useful for detecting malware with high accuracy.
引用
收藏
页码:2173 / 2183
页数:11
相关论文
共 50 条
  • [1] Empirical Evaluation of a System Call-Based Android Malware Detector
    P. Vinod
    P. Viswalakshmi
    Arabian Journal for Science and Engineering, 2018, 43 : 6751 - 6770
  • [2] A system call-based android malware detection approach with homogeneous & heterogeneous ensemble machine learning
    Bhat, Parnika
    Behal, Sunny
    Dutta, Kamlesh
    COMPUTERS & SECURITY, 2023, 130
  • [3] Empirical Evaluation of a System Call-Based Android Malware Detector
    Vinod, P.
    Viswalakshmi, P.
    ARABIAN JOURNAL FOR SCIENCE AND ENGINEERING, 2018, 43 (12) : 6751 - 6770
  • [4] System Call-based Detection of Malicious Processes
    Canzanese, Raymond
    Mancoridis, Spiros
    Kam, Moshe
    2015 IEEE INTERNATIONAL CONFERENCE ON SOFTWARE SECURITY AND RELIABILITY (QRS 2015), 2015, : 119 - 124
  • [5] Real-time system call-based ransomware detection
    Chew, Christopher Jun Wen
    Kumar, Vimal
    Patros, Panos
    Malik, Robi
    INTERNATIONAL JOURNAL OF INFORMATION SECURITY, 2024, 23 (03) : 1839 - 1858
  • [6] AN UNSUPERVISED MALWARE DETECTION SYSTEM FOR WINDOWS BASED SYSTEM CALL SEQUENCES
    Ragaventhiran, J.
    Vigneshwaran, P.
    Kodabagi, Mallikarjun M.
    Ahmed, Syed Thouheed
    Ramadoss, Prabu
    Megantoro, Prisma
    MALAYSIAN JOURNAL OF COMPUTER SCIENCE, 2022, : 79 - 92
  • [7] Android malware detection based on system call sequences and LSTM
    Xiao, Xi
    Zhang, Shaofeng
    Mercaldo, Francesco
    Hu, Guangwu
    Sangaiah, Arun Kumar
    MULTIMEDIA TOOLS AND APPLICATIONS, 2019, 78 (04) : 3979 - 3999
  • [8] Android malware detection based on system call sequences and LSTM
    Xi Xiao
    Shaofeng Zhang
    Francesco Mercaldo
    Guangwu Hu
    Arun Kumar Sangaiah
    Multimedia Tools and Applications, 2019, 78 : 3979 - 3999
  • [9] Dealing with Class Noise in Large Training Datasets for Malware Detection
    Gavrilut, Dragos
    Ciortuz, Liviu
    13TH INTERNATIONAL SYMPOSIUM ON SYMBOLIC AND NUMERIC ALGORITHMS FOR SCIENTIFIC COMPUTING (SYNASC 2011), 2012, : 401 - 407
  • [10] Noa: An information retrieval based malware detection system
    Santos, I. (isantos@deusto.es), 1600, Slovak Academy of Sciences (32):