FindMal: A file-to-file social network based malware detection framework

被引:15
|
作者
Ni, Ming [1 ]
Li, Tao [2 ,3 ]
Li, Qianmu [1 ]
Zhang, Hong [1 ]
Ye, Yanfang [4 ]
机构
[1] Nanjing Univ Sci & Technol, Sch Comp Sci & Engn, Nanjing 210094, Jiangsu, Peoples R China
[2] Florida Int Univ, Sch Comp & Informat Sci, Miami, FL 33199 USA
[3] Nanjing Univ Posts & Telecommun, Sch Comp Sci & Technol, Nanjing 210023, Jiangsu, Peoples R China
[4] West Virginia Univ, Dept Comp Sci & Elect Engn, Morgantown, WV 26506 USA
关键词
Malware detection; File relation graph; Graph feature; Label propagation; Active learning;
D O I
10.1016/j.knosys.2016.09.004
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
The rapid development of malicious software programs has posed severe threats to Computer and Internet security. Therefore, it motivates anti-malware vendors and researchers to develop novel methods which are capable of protecting users against new threats. Existing malware detectors mostly treat the file samples separately using supervised learning algorithms. However, ignoring the relationship among file samples limits the capability of malware detectors. In this paper, based on the file-to-file social network, we present a new malware detection framework, FindMal(File-to-File Social Network based Malware Detection Framework), including graph-based features extraction, Label Propagation algorithm, and active learning strategy. Nearest neighbors are first chosen as adjacent nodes for each file node to construct kNN file relation graph. Three file relation graph features are proposed to sample the representative file samples for labeling. Then, Label Propagation algorithm, which propagates the label information from labeled file samples to unlabeled files, is applied to learn the probability that one unknown file is classified as malicious or benign. A batch mode active learning method is employed to reduce the labeling cost and improve the performance of Label Propagation. Comprehensive experiments on real and large scale dataset obtained from an anti-malware company are performed. The results demonstrate that our proposed FindMal outperforms other existing detection models in classifying file samples. (C) 2016 Elsevier B.V. All rights reserved.
引用
收藏
页码:142 / 151
页数:10
相关论文
共 50 条
  • [21] Intelligent malware detection based on graph convolutional network
    Shanxi Li
    Qingguo Zhou
    Rui Zhou
    Qingquan Lv
    The Journal of Supercomputing, 2022, 78 : 4182 - 4198
  • [22] Multimodal Neural Network Based Malware Detection for Android
    Gu, Fuxuan
    Du, Zhibo
    2024 2ND INTERNATIONAL CONFERENCE ON MOBILE INTERNET, CLOUD COMPUTING AND INFORMATION SECURITY, MICCIS 2024, 2024, : 63 - 67
  • [23] A Malware Detection System Based on Heterogeneous Information Network
    Yin, Shang-Nan
    Kang, Ho-Seok
    Chen, Zhi-Guo
    Kim, Sung-Ryul
    PROCEEDINGS OF THE 2018 CONFERENCE ON RESEARCH IN ADAPTIVE AND CONVERGENT SYSTEMS (RACS 2018), 2018, : 154 - 159
  • [24] Intelligent malware detection based on graph convolutional network
    Li, Shanxi
    Zhou, Qingguo
    Zhou, Rui
    Lv, Qingquan
    JOURNAL OF SUPERCOMPUTING, 2022, 78 (03) : 4182 - 4198
  • [25] An efficient combined deep neural network based malware detection framework in 5G environment
    Lu, Ning
    Li, Dan
    Shi, Wenbo
    Vijayakumar, Pandi
    Piccialli, Francesco
    Chang, Victor
    COMPUTER NETWORKS, 2021, 189
  • [26] Dynamic VSA: a framework for malware detection based on register contents
    Ghiasi, Mahboobe
    Sami, Ashkan
    Salehi, Zahra
    ENGINEERING APPLICATIONS OF ARTIFICIAL INTELLIGENCE, 2015, 44 : 111 - 122
  • [27] A Transformer-Based Framework for Payload Malware Detection and Classification
    Stein, Kyle
    Mahyari, Arash
    Francia, Guillermo, III
    El-Sheikh, Eman
    2024 IEEE 5TH ANNUAL WORLD AI IOT CONGRESS, AIIOT 2024, 2024, : 0105 - 0111
  • [28] A Malware Detection Framework Based on Semantic Information of Behavioral Features
    Zhang, Yuxin
    Yang, Shumian
    Xu, Lijuan
    Li, Xin
    Zhao, Dawei
    APPLIED SCIENCES-BASEL, 2023, 13 (22):
  • [29] GAResNet: A Transfer Learning based Framework for Android Malware Detection
    Shen, Rui
    Zhu, Hui-juan
    Li, Chang
    Wei, Hua-hui
    2023 IEEE INTERNATIONAL CONFERENCE ON KNOWLEDGE GRAPH, ICKG, 2023, : 263 - 268
  • [30] Malicious File Detection Method Using Machine Learning and Interworking with MITRE ATT&CK Framework
    Ahn, Gwanghyun
    Kim, Kookjin
    Park, Wonhyung
    Shin, Dongkyoo
    APPLIED SCIENCES-BASEL, 2022, 12 (21):