Malware Analysis By Combining Multiple Detectors and Observation Windows

恶意软件 计算机科学 探测器 沙盒(软件开发) Android(操作系统) Android恶意软件 利用 逃避(道德) 假阳性率 人工智能 实时计算 数据挖掘 机器学习 操作系统 计算机安全 电信 免疫系统 免疫学 生物
作者
Massimo Ficco
出处
期刊:IEEE Transactions on Computers [Institute of Electrical and Electronics Engineers]
卷期号:: 1-1 被引量:62
标识
DOI:10.1109/tc.2021.3082002
摘要

Malware developers continually attempt to modify the execution pattern of malicious code hiding it inside apparent normal applications, which makes its detection and classification challenging. This paper proposes an ensemble detector, which exploits the capabilities of the main analysis algorithms proposed in the literature designed to offer greater resilience to specific evasion techniques. In particular, the paper presents different methods to optimally combine both generic and specialized detectors during the analysis process, which can be used to increase the unpredictability of the detection strategy, as well as improve the detection rate in presence of unknown malware families and provide better detection performance in the absence of a constant re-training of detector needed to cope with the evolution of malware. The paper also presents an alpha-count mechanism that explores how the length of the observation time window can affect the detection accuracy and speed of different combinations of detectors during the malware analysis. An extended experimental campaign has been conducted on both an open-source sandbox and an Android smartphone with different malware datasets. A trade-off among performance, training time, and mean-time-to-detect is presented. Finally, a comparison with other ensemble detectors is also presented.
最长约 10秒,即可获得该文献文件

科研通智能强力驱动
Strongly Powered by AbleSci AI
科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
欢呼怜烟完成签到,获得积分10
刚刚
香蕉觅云应助月亮moon采纳,获得10
刚刚
Johnpick应助yufeng采纳,获得10
1秒前
搜集达人应助hui采纳,获得10
1秒前
CooperLI发布了新的文献求助10
2秒前
sss发布了新的文献求助10
2秒前
2秒前
Zn应助塔图姆采纳,获得10
2秒前
研友_VZG7GZ应助xlp采纳,获得10
3秒前
3秒前
龙傲天发布了新的文献求助10
3秒前
深情安青应助眼睛大天思采纳,获得10
4秒前
lili发布了新的文献求助10
5秒前
elebug发布了新的文献求助10
5秒前
DC完成签到,获得积分10
5秒前
biofresh完成签到,获得积分10
5秒前
小柒完成签到,获得积分10
5秒前
苏卿应助FceEar采纳,获得10
5秒前
zhaoli发布了新的文献求助10
6秒前
小镇青年完成签到,获得积分10
6秒前
6秒前
7秒前
8秒前
8秒前
bkagyin应助复杂汉堡采纳,获得10
8秒前
百十余完成签到,获得积分10
9秒前
luo完成签到,获得积分20
9秒前
搜集达人应助Daisy采纳,获得10
9秒前
拜拜完成签到,获得积分10
9秒前
酷炫蛋挞完成签到 ,获得积分10
10秒前
10秒前
爆米花应助Fancy采纳,获得10
10秒前
11秒前
zhanglan发布了新的文献求助10
11秒前
Hello应助你好采纳,获得10
11秒前
11秒前
科研通AI5应助Selenge采纳,获得10
12秒前
长情半邪发布了新的文献求助10
12秒前
jackone发布了新的文献求助30
12秒前
13秒前
高分求助中
Continuum Thermodynamics and Material Modelling 3000
Production Logging: Theoretical and Interpretive Elements 2700
Mechanistic Modeling of Gas-Liquid Two-Phase Flow in Pipes 2500
Kelsen’s Legacy: Legal Normativity, International Law and Democracy 1000
Handbook on Inequality and Social Capital 800
Conference Record, IAS Annual Meeting 1977 610
Interest Rate Modeling. Volume 3: Products and Risk Management 600
热门求助领域 (近24小时)
化学 材料科学 生物 医学 工程类 有机化学 生物化学 物理 纳米技术 计算机科学 内科学 化学工程 复合材料 基因 遗传学 物理化学 催化作用 量子力学 光电子学 冶金
热门帖子
关注 科研通微信公众号,转发送积分 3546979
求助须知:如何正确求助?哪些是违规求助? 3123961
关于积分的说明 9357531
捐赠科研通 2822555
什么是DOI,文献DOI怎么找? 1551574
邀请新用户注册赠送积分活动 723561
科研通“疑难数据库(出版商)”最低求助积分说明 713801