RAMD: registry-based anomaly malware detection using one-class ensemble classifiers

被引:0
|
作者
Asghar Tajoddin
Mahdi Abadi
机构
[1] Tarbiat Modares University,School of Electrical and Computer Engineering
来源
Applied Intelligence | 2019年 / 49卷
关键词
Windows malware; Registry-based malware detection; Ensemble classifier; One-class classification; Pruning algorithm; Memetic firefly algorithm; Aggregation operator; Superincreasing ordered weighted averaging;
D O I
暂无
中图分类号
学科分类号
摘要
Malware is continuously evolving and becoming more sophisticated to avoid detection. Traditionally, the Windows operating system has been the most popular target for malware writers because of its dominance in the market of desktop operating systems. However, despite a large volume of new Windows malware samples that are collected daily, there is relatively little research focusing on Windows malware. The Windows Registry, or simply the registry, is very heavily used by programs in Windows, making it a good source for detecting malicious behavior. In this paper, we present RAMD, a novel approach that uses an ensemble classifier consisting of multiple one-class classifiers to detect known and especially unknown malware abusing registry keys and values for malicious intent. RAMD builds a model of registry behavior of benign programs and then uses this model to detect malware by looking for anomalous registry accesses. In detail, it constructs an initial ensemble classifier by training multiple one-class classifiers and then applies a novel swarm intelligence pruning algorithm, called memetic firefly-based ensemble classifier pruning (MFECP), on the ensemble classifier to reduce its size by selecting only a subset of one-class classifiers that are highly accurate and have diversity in their outputs. To combine the outputs of one-class classifiers in the pruned ensemble classifier, RAMD uses a specific aggregation operator, called Fibonacci-based superincreasing ordered weighted averaging (FSOWA). The results of our experiments performed on a dataset of benign and malware samples show that RAMD can achieve about 98.52% detection rate, 2.19% false alarm rate, and 98.43% accuracy.
引用
收藏
页码:2641 / 2658
页数:17
相关论文
共 50 条
  • [21] Ensemble one-class classifiers based on hybrid diversity generation and pruning
    Liu, Jia-Chen
    Miao, Qi-Guang
    Cao, Ying
    Song, Jian-Feng
    Quan, Yi-Ning
    Dianzi Yu Xinxi Xuebao/Journal of Electronics and Information Technology, 2015, 37 (02): : 386 - 393
  • [22] Improving performance of one-class classifiers applied to anomaly detection in oil wells
    Machado, Andre Paulo Ferreira
    Vargas, Ricardo Emanuel Vaz
    Ciarelli, Patrick Marques
    Munaro, Celso Jose
    JOURNAL OF PETROLEUM SCIENCE AND ENGINEERING, 2022, 218
  • [23] Malware Detection for Internet of Things Using One-Class Classification
    Shi, Tongxin
    McCann, Roy A.
    Huang, Ying
    Wang, Wei
    Kong, Jun
    SENSORS, 2024, 24 (13)
  • [24] IoT Botnet Detection Using Various One-Class Classifiers
    Raj, Mehedi Hasan
    Rahman, A. N. M. Asifur
    Akter, Umma Habiba
    Riya, Khayrun Nahar
    Nijhum, Anika Tasneem
    Rahman, Rashedur M.
    VIETNAM JOURNAL OF COMPUTER SCIENCE, 2021, 8 (02) : 291 - 310
  • [25] Fault detection using bispectral features and one-class classifiers
    Du, Xian
    JOURNAL OF PROCESS CONTROL, 2019, 83 : 1 - 10
  • [26] Dynamic ensemble selection for multi -class classification with one-class classifiers
    Krawczyk, Bartosz
    Galar, Mikel
    Wozniak, Michal
    Bustince, Humberto
    Herrera, Francisco
    PATTERN RECOGNITION, 2018, 83 : 34 - 51
  • [27] Ensemble One-Class Classification Applied for Anomaly Detection in Process Control Systems
    Lu, Shengji
    Wang, Biao
    2017 29TH CHINESE CONTROL AND DECISION CONFERENCE (CCDC), 2017, : 6589 - 6592
  • [28] Acoustic Event Classification Using Ensemble of One-Class Classifiers for Monitoring Application
    Tripathi, Achyut Mani
    Baruah, Diganta
    Baruah, Rashmi Dutta
    2015 IEEE SYMPOSIUM SERIES ON COMPUTATIONAL INTELLIGENCE (IEEE SSCI), 2015, : 1681 - 1686
  • [29] Clustering-Based Ensemble of One-Class Classifiers for Hyperspectral Image Segmentation
    Krawczyk, Bartosz
    Wozniak, Michal
    Cyganek, Boguslaw
    HYBRID ARTIFICIAL INTELLIGENCE SYSTEMS, HAIS 2014, 2014, 8480 : 678 - 688
  • [30] Active Learning for One-Class Classification Using Two One-Class Classifiers
    Schlachter, Patrick
    Yang, Bin
    2018 26TH EUROPEAN SIGNAL PROCESSING CONFERENCE (EUSIPCO), 2018, : 1197 - 1201