Machine Learning Approaches to Malicious PowerShell Scripts Detection and Feature Combination Analysis

被引:1
|
作者
Hung, Hsiang-Hua [1 ]
Chen, Jiann-Liang [1 ]
Ma, Yi-Wei [1 ]
机构
[1] Natl Taiwan Univ Sci & Technol, Dept Elect Engn, Taipei, Taiwan
来源
JOURNAL OF INTERNET TECHNOLOGY | 2024年 / 25卷 / 01期
关键词
Machine learning; XGBoost; PowerShell; Malicious scripts; Behavioral features analysis;
D O I
10.53106/160792642024012501014
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
With advances in communication technology, modern society relies more than ever on the Internet and various userfriendly digital tools. It provides access to and enables the manipulation of files, trips, and the Windows API. Attackers frequently use various obfuscation techniques PowerShell scripts to avoid detection by anti -virus software. Their doing so can significantly reduce the readability of the script. This work statically analyzes PowerShell scripts. Thirty-three features that were based on the script's keywords, format, and string combinations were used herein to determine the behavioral intent of the script. Ones are characteristicbased features that are obtained by calculation; the others are behavior -based features that determine the execution function of behavior using keywords and instructions. Behavior -based features can be divided into positive behavior -based features, neutral behavior -based features, and negative behaviorbased features. These three types of features are enhanced by observing samples and adding keywords. The other type of characteristic -based feature is introduced into the formula from other studies in this work. The XGBoost model was used to evaluate the importance of the features that are proposed in this study and to identify the combination of features that contributed most to the detection of PowerShell scripts. The final model with the combined features is found to exhibit the best performance. The model has 99.27% accuracy when applied to the validation dataset. The results clearly indicate that the proposed malicious PowerShell script detection model outperforms previously developed models.
引用
收藏
页码:167 / 173
页数:7
相关论文
共 50 条
  • [41] Evaluation of Machine Learning Algorithms for Detection of Malicious Traffic in SCADA Network
    L. Rajesh
    Penke Satyanarayana
    Journal of Electrical Engineering & Technology, 2022, 17 : 913 - 928
  • [42] Covert Channel Detection: Machine Learning Approaches
    Elsadig, Muawia A.
    Gafar, Ahmed
    IEEE ACCESS, 2022, 10 : 38391 - 38405
  • [43] Feature Reduction and Anomaly Detection in IoT Using Machine Learning Algorithms
    Hamdan, Adel
    Tahboush, Muhannad
    Adawy, Mohammad
    Alwada'n, Tariq
    Ghwanmeh, Sameh
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2025, 16 (01) : 463 - 470
  • [44] Machine Learning Approaches to Maritime Anomaly Detection
    Obradovic, Ines
    Milicevic, Mario
    Zubrinic, Krunoslav
    NASE MORE, 2014, 61 (5-6): : 96 - 101
  • [45] FeatureSelect: a software for feature selection based on machine learning approaches
    Masoudi-Sobhanzadeh, Yosef
    Motieghader, Habib
    Masoudi-Nejad, Ali
    BMC BIOINFORMATICS, 2019, 20 (1)
  • [46] FeatureSelect: a software for feature selection based on machine learning approaches
    Yosef Masoudi-Sobhanzadeh
    Habib Motieghader
    Ali Masoudi-Nejad
    BMC Bioinformatics, 20
  • [47] An Exploratory Analysis of Feature Selection for Malware Detection with Simple Machine Learning Algorithms
    Rahman, Md Ashikur
    Islam, Syful
    Nugroho, Yusuf Sulistyo
    Al Irsyadi, Fatah Yasin
    Hossain, Md Javed
    JOURNAL OF COMMUNICATIONS SOFTWARE AND SYSTEMS, 2023, 19 (03) : 207 - 219
  • [48] Domain generated algorithms detection applying a combination of a deep feature selection and traditional machine learning models
    Hassaoui, Mohamed
    Hanini, Mohamed
    El Kafhali, Said
    JOURNAL OF COMPUTER SECURITY, 2023, 31 (01) : 85 - 105
  • [49] Comparative analysis of Machine Learning approaches for early stage Cervical Spondylosis detection
    Sreeraj, M.
    Joy, Jestin
    Jose, Manu
    Varghese, Meenu
    Rejoice, T. J.
    JOURNAL OF KING SAUD UNIVERSITY-COMPUTER AND INFORMATION SCIENCES, 2022, 34 (06) : 3301 - 3309
  • [50] Machine Learning and Deep Learning Approaches for Guava Disease Detection
    K. Paramesha
    Shruti Jalapur
    Shalini Hanok
    Kiran Puttegowda
    G. Manjunatha
    Bharath Kumara
    SN Computer Science, 6 (4)