• DocumentCode
    3688613
  • Title

    Valkyrie: Behavioral malware detection using global kernel-level telemetry data

  • Author

    Sven Krasser;Brett Meyer;Patrick Crenshaw

  • Author_Institution
    CrowdStrike, Inc.
  • fYear
    2015
  • Firstpage
    1
  • Lastpage
    6
  • Abstract
    The growth in malware remains a major challenge to Internet security. In this paper, we present Valkyrie, a classification system that is able to identify malicious binaries purely based on behavioral traits gathered from large-scale telemetry submitted by endhosts using a lightweight sensor component. Valkyrie utilizes the Apache Spark data processing framework and is therefore able to process a large volume of real-world data in a short amount of time. In addition, since Valkyrie conducts all its heavy computation in the cloud, it therefore imposes minimal load on endpoints. Valkyrie achieves high confidence predictions at a very low false positive rate, making it a suitable solution for use with production systems.
  • Keywords
    "Malware","Feature extraction","Sparks","Support vector machines","Training data","Measurement","Telemetry"
  • Publisher
    ieee
  • Conference_Titel
    Machine Learning for Signal Processing (MLSP), 2015 IEEE 25th International Workshop on
  • Type

    conf

  • DOI
    10.1109/MLSP.2015.7324334
  • Filename
    7324334