Title :
Analysis of Malware behavior: Type classification using machine learning
Author :
Pirscoveanu, Radu S. ; Hansen, Steven S. ; Larsen, Thor M. T. ; Stevanovic, Matija ; Pedersen, Jens Myrup ; Czech, Alexandre
Author_Institution :
Aalborg Univ., Aalborg, Denmark
Abstract :
Malicious software has become a major threat to modern society, not only due to the increased complexity of the malware itself but also due to the exponential increase of new malware each day. This study tackles the problem of analyzing and classifying a high amount of malware in a scalable and automatized manner. We have developed a distributed malware testing environment by extending Cuckoo Sandbox that was used to test an extensive number of malware samples and trace their behavioral data. The extracted data was used for the development of a novel type classification approach based on supervised machine learning. The proposed classification approach employs a novel combination of features that achieves a high classification rate with a weighted average AUC value of 0.98 using Random Forests classifier. The approach has been extensively tested on a total of 42,000 malware samples. Based on the above results it is believed that the developed system can be used to pre-filter novel from known malware in a future malware analysis system.
Keywords :
invasive software; learning (artificial intelligence); pattern classification; Cuckoo Sandbox; behavioral data; distributed malware testing environment; machine learning; malicious software; malware analysis system; malware behavior analysis; malware samples; random forest classifier; supervised machine learning; type classification approach; weighted average AUC value; Data mining; Feature extraction; Testing; Training; Trojan horses; Vegetation; API call; Cuckoo sandbox; Malware; Random Forests; dynamic analysis; feature selection; scalability; supervised machine learning; type-classification;
Conference_Titel :
Cyber Situational Awareness, Data Analytics and Assessment (CyberSA), 2015 International Conference on
Conference_Location :
London
DOI :
10.1109/CyberSA.2015.7166115