Novel set of general descriptive features for enhanced detection of malicious emails using machine learning methods

被引:22
|
作者
Cohen, Aviad [1 ,2 ]
Nissim, Nir [1 ,3 ]
Elovici, Yuval [1 ,2 ]
机构
[1] Ben Gurion Univ Negev, Cyber Secur Res Ctr, Malware Lab, Beer Sheva, Israel
[2] Ben Gurion Univ Negev, Dept Software & Informat Syst Engn, Beer Sheva, Israel
[3] Ben Gurion Univ Negev, Dept Ind Engn & Management, Beer Sheva, Israel
关键词
Email; Detection; Machine learning; Analysis; Malware; Features; CLASSIFICATION; ACCURACY; AUC;
D O I
10.1016/j.eswa.2018.05.031
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
In recent years, cyber-attacks against businesses and organizations have increased. Such attacks usually result in significant damage to the organization, such as the loss and/or leakage of sensitive and confidential information. Because email communication is an integral part of daily business operations, attackers frequently leverage email as an attack vector in order to initially penetrate the targeted organization. Email message allows the attacker to deliver dangerous content to the victim, such as malicious attachments or links to malicious websites. Existing email analysis solutions analyze only specific parts of the email using rule-based methods, while other important parts remain unanalyzed. Existing anti-virus engines primarily use signature-based detection methods, and therefore are insufficient for detecting new unknown malicious emails. Machine learning methods have been shown to be effective at detecting maliciousness in various domains and particularly in email. Previous works which used machine learning methods suggested sets of features which offer a limited perspective over the whole email message. In this paper, we propose a novel set of general descriptive features extracted from all email components (header, body, and attachments) for enhanced detection of malicious emails using machine learning methods. The proposed features are extracted just from the email itself; therefore, our features are independent, since the extraction process does not require an Internet connection or the use of external services or other tools, thereby meeting the needs of real-time detection systems. We conducted an extensive evaluation of our new novel features against sets of features suggested by previous academic work using a collection of 33,142 emails which contains 38.73% malicious and 61.27% benign emails. The results show that malicious emails can be detected effectively when using our novel features with machine learning algorithms. Moreover, our novel features enhance the detection of malicious emails when used in conjunction with features suggested by related work. The Random Forest classifier achieved the highest detection rates, with an AUC of 0.929, true positive rate (TPR) of 0.947, and false positive rate (FPR) of 0.03. We also present the IDR (integrated detection rate), a new measure which helps calibrate the threshold of a machine learning classifier in order to achieve the optimal TP and FP rates, which are the most important measures for a real-time and practical cyber-security application. (C) 2018 Elsevier Ltd. All rights reserved.
引用
收藏
页码:143 / 169
页数:27
相关论文
共 50 条
  • [1] Trusted detection of ransomware in a private cloud using machine learning methods leveraging meta-features from volatile memory
    Cohen, Aviad
    Nissim, Nir
    EXPERT SYSTEMS WITH APPLICATIONS, 2018, 102 : 158 - 178
  • [2] Malicious URL Detection Using Machine Learning
    Hani, Dr Raed Bani
    Amoura, Motasem
    Ammourah, Mohammad
    Abu Khalil, Yazeed
    2024 15TH INTERNATIONAL CONFERENCE ON INFORMATION AND COMMUNICATION SYSTEMS, ICICS 2024, 2024,
  • [3] Categorizing Emails Using Machine Learning with Textual Features
    Zhang, Haoran
    Rangrej, Jagadish
    Rais, Saad
    Hillmer, Michael
    Rudzicz, Frank
    Malikov, Kamil
    ADVANCES IN ARTIFICIAL INTELLIGENCE, 2019, 11489 : 3 - 15
  • [4] Lexical features based malicious URL detection using machine learning techniques
    Saleem Raja, A.
    Vinodini, R.
    Kavitha, A.
    MATERIALS TODAY-PROCEEDINGS, 2021, 47 : 163 - 166
  • [5] Detection of malicious URLs using machine learning
    Reyes-Dorta, Nuria
    Caballero-Gil, Pino
    Rosa-Remedios, Carlos
    WIRELESS NETWORKS, 2024, 30 (09) : 7543 - 7560
  • [6] MalDC: Malicious Software Detection and Classification using Machine Learning
    Moon, Jaewoong
    Kim, Subin
    Jangyong, Park
    Lee, Jieun
    Kim, Kyungshin
    Song, Jaeseung
    KSII TRANSACTIONS ON INTERNET AND INFORMATION SYSTEMS, 2022, 16 (05): : 1466 - 1488
  • [7] Features of Detecting Malicious Installation Files Using Machine Learning Algorithms
    Yugai, P. E.
    Zhukovskii, E. V.
    Semenov, P. O.
    AUTOMATIC CONTROL AND COMPUTER SCIENCES, 2023, 57 (08) : 968 - 974
  • [8] Features of Detecting Malicious Installation Files Using Machine Learning Algorithms
    P. E. Yugai
    E. V. Zhukovskii
    P. O. Semenov
    Automatic Control and Computer Sciences, 2023, 57 : 968 - 974
  • [9] SFEM: Structural feature extraction methodology for the detection of malicious office documents using machine learning methods
    Cohen, Aviad
    Nissim, Nir
    Rokach, Lior
    Elovici, Yuval
    EXPERT SYSTEMS WITH APPLICATIONS, 2016, 63 : 324 - 343
  • [10] Malware detection using image-based features and machine learning methods
    Gungor, Aslihan
    Dogru, Ibrahim Alper
    Barisci, Necaattin
    Toklu, Sinan
    JOURNAL OF THE FACULTY OF ENGINEERING AND ARCHITECTURE OF GAZI UNIVERSITY, 2023, 38 (03): : 1781 - 1792