A Malware Detection Approach Based on Feature Engineering and Behavior Analysis

Por favor, use este identificador para citar o enlazar este ítem: http://hdl.handle.net/10045/137642
Información del item - Informació de l'item - Item information
Título: A Malware Detection Approach Based on Feature Engineering and Behavior Analysis
Autor/es: Torres, Manuel | Alvarez, Rafael | Cazorla, Miguel
Grupo/s de investigación o GITE: Robótica y Visión Tridimensional (RoViT) | Criptología y Seguridad Computacional
Centro, Departamento o Servicio: Universidad de Alicante. Departamento de Ciencia de la Computación e Inteligencia Artificial
Palabras clave: Convolutional neural networks | Dataset | Machine learning | Malware
Fecha de publicación: 25-sep-2023
Editor: IEEE
Cita bibliográfica: IEEE Access. 2023, 11: 105355-105367. https://doi.org/10.1109/ACCESS.2023.3319093
Resumen: Cybercriminals are constantly developing new techniques to circumvent the security measures implemented by experts and researchers, so malware is able to evolve very rapidly. In addition, detecting malware across multiple systems is a challenging problem because each computing environment has its own unique characteristics. Traditional techniques, such as signature-based malware detection, have been largely replaced by more modern approaches, such as machine learning and robust cross-platform behavior-based threat detection, as they have become less effective. Researchers employ these techniques across a variety of data sources, including network traffic, binaries, and behavioral data, to extract relevant features and feed them to models for accurate prediction. The aim of this research is to provide a novel dataset comprised of a substantial number of high-quality samples based on software behavior. Due to the lack of a standard representational format for malware behavior in current research, we also present an innovative method for representing malware behavior by converting API calls into 2D images, which builds on previous work. Additionally, we propose and describe the implementation of a new machine learning model based on binary classification (malware or benign software) using the previously mentioned novel dataset as its data source, thereby establishing an evaluation baseline. We have conducted extensive experimentation, validating the proposed model with both our novel dataset and real-world data. In terms of metrics, our proposed model outperforms a well-known model that is also based on behavior analysis and has a similar architecture.
URI: http://hdl.handle.net/10045/137642
ISSN: 2169-3536
DOI: 10.1109/ACCESS.2023.3319093
Idioma: eng
Tipo: info:eu-repo/semantics/article
Derechos: This work is licensed under a Creative Commons Attribution 4.0 License. For more information, see https://creativecommons.org/licenses/by/4.0/
Revisión científica: si
Versión del editor: https://doi.org/10.1109/ACCESS.2023.3319093
Aparece en las colecciones:INV - CSC - Artículos de Revistas
INV - RoViT - Artículos de Revistas

Archivos en este ítem:
Archivos en este ítem:
Archivo Descripción TamañoFormato 
ThumbnailTorres_etal_2023_IEEEAccess.pdf1,64 MBAdobe PDFAbrir Vista previa


Todos los documentos en RUA están protegidos por derechos de autor. Algunos derechos reservados.