Machine Learning Approaches to Malicious PowerShell Scripts Detection and Feature Combination Analysis

被引:1
|
作者
Hung, Hsiang-Hua [1 ]
Chen, Jiann-Liang [1 ]
Ma, Yi-Wei [1 ]
机构
[1] Natl Taiwan Univ Sci & Technol, Dept Elect Engn, Taipei, Taiwan
来源
JOURNAL OF INTERNET TECHNOLOGY | 2024年 / 25卷 / 01期
关键词
Machine learning; XGBoost; PowerShell; Malicious scripts; Behavioral features analysis;
D O I
10.53106/160792642024012501014
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
With advances in communication technology, modern society relies more than ever on the Internet and various userfriendly digital tools. It provides access to and enables the manipulation of files, trips, and the Windows API. Attackers frequently use various obfuscation techniques PowerShell scripts to avoid detection by anti -virus software. Their doing so can significantly reduce the readability of the script. This work statically analyzes PowerShell scripts. Thirty-three features that were based on the script's keywords, format, and string combinations were used herein to determine the behavioral intent of the script. Ones are characteristicbased features that are obtained by calculation; the others are behavior -based features that determine the execution function of behavior using keywords and instructions. Behavior -based features can be divided into positive behavior -based features, neutral behavior -based features, and negative behaviorbased features. These three types of features are enhanced by observing samples and adding keywords. The other type of characteristic -based feature is introduced into the formula from other studies in this work. The XGBoost model was used to evaluate the importance of the features that are proposed in this study and to identify the combination of features that contributed most to the detection of PowerShell scripts. The final model with the combined features is found to exhibit the best performance. The model has 99.27% accuracy when applied to the validation dataset. The results clearly indicate that the proposed malicious PowerShell script detection model outperforms previously developed models.
引用
收藏
页码:167 / 173
页数:7
相关论文
共 50 条
  • [31] Comparative Analysis of Features Based Machine Learning Approaches for Phishing Detection
    Jain, Ankit Kumar
    Gupta, B. B.
    PROCEEDINGS OF THE 10TH INDIACOM - 2016 3RD INTERNATIONAL CONFERENCE ON COMPUTING FOR SUSTAINABLE GLOBAL DEVELOPMENT, 2016, : 2125 - 2130
  • [32] Comparison of Multiple Machine Learning Approaches and Sentiment Analysis in Detection of Spam
    Alam, A. N. M. Sajedul
    Zaman, Shifat
    Dey, Arnob Kumar
    Bin Kibria, Junaid
    Alam, Zawad
    Mahbub, Mohammed Julfikar Ali
    Mahtab, Md. Motahar
    Rasel, Annajiat Alim
    ADVANCES IN COMPUTING AND DATA SCIENCES (ICACDS 2022), PT I, 2022, 1613 : 37 - 50
  • [33] Machine learning approaches in medical image analysis: From detection to diagnosis
    de Bruijne, Marleen
    MEDICAL IMAGE ANALYSIS, 2016, 33 : 94 - 97
  • [34] Accuracy Improvement Method for Malicious Domain Detection using Machine Learning
    Koga, Toshiki
    Nobayashi, Daiki
    Ikenaga, Takeshi
    2024 IEEE 21ST CONSUMER COMMUNICATIONS & NETWORKING CONFERENCE, CCNC, 2024, : 1108 - 1109
  • [35] MalJPEG: Machine Learning Based Solution for the Detection of Malicious JPEG Images
    Cohen, Aviad
    Nissim, Nir
    Elovici, Yuval
    IEEE ACCESS, 2020, 8 (08) : 19997 - 20011
  • [36] Applying machine learning techniques for detection of malicious code in network traffic
    Elovici, Yuval
    Shabtai, Asaf
    Moskovitch, Robert
    Tahan, Gil
    Glezer, Chanan
    KI 2007: ADVANCES IN ARTIFICIAL INTELLIGENCE, PROCEEDINGS, 2007, 4667 : 44 - +
  • [37] Active Malicious Accounts Detection with Multimodal Fusion Machine Learning Algorithm
    Tang, Yuting
    Zhang, Dafang
    Liang, Wei
    Li, Kuan-Ching
    Sukhija, Nitin
    UBIQUITOUS SECURITY, 2022, 1557 : 38 - 52
  • [38] Evaluation of Machine Learning Algorithms for Detection of Malicious Traffic in SCADA Network
    Rajesh, L.
    Satyanarayana, Penke
    JOURNAL OF ELECTRICAL ENGINEERING & TECHNOLOGY, 2022, 17 (02) : 913 - 928
  • [39] An Intelligent Detection of Malicious Intrusions in IoT Based on Machine Learning and Deep Learning Techniques
    Iftikhar, Saman
    Khan, Danish
    Al-Madani, Daniah
    Alheeti, Khattab M. Ali
    Fatima, Kiran
    COMPUTER SCIENCE JOURNAL OF MOLDOVA, 2022, 30 (03) : 288 - 307
  • [40] Explainable machine learning for phishing feature detection
    Calzarossa, Maria Carla
    Giudici, Paolo
    Zieni, Rasha
    QUALITY AND RELIABILITY ENGINEERING INTERNATIONAL, 2024, 40 (01) : 362 - 373