RAMD: registry-based anomaly malware detection using one-class ensemble classifiers

被引:0
|
作者
Asghar Tajoddin
Mahdi Abadi
机构
[1] Tarbiat Modares University,School of Electrical and Computer Engineering
来源
Applied Intelligence | 2019年 / 49卷
关键词
Windows malware; Registry-based malware detection; Ensemble classifier; One-class classification; Pruning algorithm; Memetic firefly algorithm; Aggregation operator; Superincreasing ordered weighted averaging;
D O I
暂无
中图分类号
学科分类号
摘要
Malware is continuously evolving and becoming more sophisticated to avoid detection. Traditionally, the Windows operating system has been the most popular target for malware writers because of its dominance in the market of desktop operating systems. However, despite a large volume of new Windows malware samples that are collected daily, there is relatively little research focusing on Windows malware. The Windows Registry, or simply the registry, is very heavily used by programs in Windows, making it a good source for detecting malicious behavior. In this paper, we present RAMD, a novel approach that uses an ensemble classifier consisting of multiple one-class classifiers to detect known and especially unknown malware abusing registry keys and values for malicious intent. RAMD builds a model of registry behavior of benign programs and then uses this model to detect malware by looking for anomalous registry accesses. In detail, it constructs an initial ensemble classifier by training multiple one-class classifiers and then applies a novel swarm intelligence pruning algorithm, called memetic firefly-based ensemble classifier pruning (MFECP), on the ensemble classifier to reduce its size by selecting only a subset of one-class classifiers that are highly accurate and have diversity in their outputs. To combine the outputs of one-class classifiers in the pruned ensemble classifier, RAMD uses a specific aggregation operator, called Fibonacci-based superincreasing ordered weighted averaging (FSOWA). The results of our experiments performed on a dataset of benign and malware samples show that RAMD can achieve about 98.52% detection rate, 2.19% false alarm rate, and 98.43% accuracy.
引用
收藏
页码:2641 / 2658
页数:17
相关论文
共 50 条
  • [31] Ensemble of One-Class Classifiers for Detecting Faults in Induction Motors
    Zare, Shokoofeh
    Razavi-Far, Roozbeh
    Saif, Mehrdad
    Zarei, Jafar
    2018 IEEE CANADIAN CONFERENCE ON ELECTRICAL & COMPUTER ENGINEERING (CCECE), 2018,
  • [32] Malware Detection With Subspace Learning-Based One-Class Classification
    Al-Khshali, Hasan H.
    Ilyas, Muhammad
    Sohrab, Fahad
    Gabbouj, Moncef
    IEEE ACCESS, 2024, 12 : 81017 - 81029
  • [33] Steganography anomaly detection using simple one-class classification
    Rodriguez, Benjamin M.
    Peterson, Gilbert L.
    Agaian, Sos S.
    MOBILE MULTIMEDIA/IMAGE PROCESSING FOR MILITARY AND SECURITY APPLICATIONS 2007, 2007, 6579
  • [34] Anomaly Detection using Clustered Deep One-Class Classification
    Kim, Younghwan
    Kim, Huy Kang
    2020 15TH ASIA JOINT CONFERENCE ON INFORMATION SECURITY (ASIAJCIS 2020), 2020, : 151 - 157
  • [35] Anomaly detection for medical images based on a one-class classification
    Wei, Qi
    Ren, Yinhao
    Hou, Rui
    Shi, Bibo
    Lo, Joseph Y.
    Carin, Lawrence
    MEDICAL IMAGING 2018: COMPUTER-AIDED DIAGNOSIS, 2018, 10575
  • [36] DAD: A Distributed Anomaly Detection system using ensemble one-class statistical learning in edge networks
    Moustafa, Nour
    Keshk, Marwa
    Choo, Kim-Kwang Raymond
    Lynar, Timothy
    Camtepe, Seyit
    Whitty, Monica
    FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2021, 118 : 240 - 251
  • [37] Active anomaly detection based on deep one-class classification
    Kim, Minkyung
    Kim, Junsik
    Yu, Jongmin
    Choi, Jun Kyun
    PATTERN RECOGNITION LETTERS, 2023, 167 : 18 - 24
  • [38] Visual Object Detection Using Cascades of Binary and One-Class Classifiers
    Cevikalp, Hakan
    Triggs, Bill
    INTERNATIONAL JOURNAL OF COMPUTER VISION, 2017, 123 (03) : 334 - 349
  • [39] Visual Object Detection Using Cascades of Binary and One-Class Classifiers
    Hakan Cevikalp
    Bill Triggs
    International Journal of Computer Vision, 2017, 123 : 334 - 349
  • [40] Multi-class classification via heterogeneous ensemble of one-class classifiers
    Kang, Seokho
    Cho, Sungzoon
    Rang, Pilsung
    ENGINEERING APPLICATIONS OF ARTIFICIAL INTELLIGENCE, 2015, 43 : 35 - 43