Malware Detection Based on Multidimensional Time Distribution Features

Huizhong Sun, Guosheng Xu, Hewei Yu, Minyan Ma, Yanhui Guo, Ruijie Quan
{"title":"Malware Detection Based on Multidimensional Time Distribution Features","authors":"Huizhong Sun, Guosheng Xu, Hewei Yu, Minyan Ma, Yanhui Guo, Ruijie Quan","doi":"10.32604/jqc.2021.017365","DOIUrl":null,"url":null,"abstract":": Language detection models based on system calls suffer from certain false negatives and detection blind spots. Hence, the normal behavior sequences of some malware applications for a short period can become malicious behavior within a certain time window. To detect such behaviors, we extract a multidimensional time distribution feature matrix on the basis of statistical analysis. This matrix mainly includes multidimensional time distribution features, multidimensional word pair correlation features, and multidimensional word frequency distribution features. A multidimensional time distribution model based on neural networks is built to detect the overall abnormal behavior within a given time window. Experimental evaluation is conducted using the ADFA-LD dataset. Accuracy, precision, and recall are used as the measurement indicators of the model. An accuracy rate of 95.26% and a recall rate of 96.11% are achieved.","PeriodicalId":284655,"journal":{"name":"Journal of Quantum Computing","volume":"45 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"1900-01-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Journal of Quantum Computing","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.32604/jqc.2021.017365","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

Abstract

: Language detection models based on system calls suffer from certain false negatives and detection blind spots. Hence, the normal behavior sequences of some malware applications for a short period can become malicious behavior within a certain time window. To detect such behaviors, we extract a multidimensional time distribution feature matrix on the basis of statistical analysis. This matrix mainly includes multidimensional time distribution features, multidimensional word pair correlation features, and multidimensional word frequency distribution features. A multidimensional time distribution model based on neural networks is built to detect the overall abnormal behavior within a given time window. Experimental evaluation is conducted using the ADFA-LD dataset. Accuracy, precision, and recall are used as the measurement indicators of the model. An accuracy rate of 95.26% and a recall rate of 96.11% are achieved.
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
基于多维时间分布特征的恶意软件检测
基于系统调用的语言检测模型存在一定的假阴性和检测盲点。因此,一些恶意软件应用程序在短时间内的正常行为序列可能会在某个时间窗口内变成恶意行为。为了检测这些行为,我们在统计分析的基础上提取了一个多维时间分布特征矩阵。该矩阵主要包括多维时间分布特征、多维词对相关特征和多维词频分布特征。建立了基于神经网络的多维时间分布模型来检测给定时间窗口内的整体异常行为。使用ADFA-LD数据集进行实验评估。准确度、精密度和召回率作为模型的度量指标。准确率为95.26%,召回率为96.11%。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
Quantum Cryptography–A Theoretical Overview An Ui Design Optimization Strategy for General App in Big Data Environment Analysis and Test on Influence Factors of Dew Drop Condensation in Dew Point Hygrometer Interpretation of the Entangled States T Application of MES System in the Safety Management of Offshore Oil and Gas Fields
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1