DocumentCode :
3705121
Title :
Pruned feature space for metamorphic malware detection using Markov Blanket
Author :
Jithu Raphel; Vinod P.
Author_Institution :
Department of Computer Science, SCMS School of Engineering & Technology, Ernakulam, Kerala, India
fYear :
2015
Firstpage :
377
Lastpage :
382
Abstract :
The proposed non-signature based system creates a meta feature space for the detection of metamorphic malware samples where three sets of features are extracted from the files: (a) branch opcodes (b) unigrams (c) bigrams. The feature space is initially pruned using Naïve Bayes method. After the rare feature elimination process, the relevant opcodes that are highly contributing towards the target class are selected, thereby forming a relevant feature set. Next phase is to remove the redundant features that are present in the relevant feature set using the Markov Blanket approach. Prominent features extracted are used for generating the training models and unseen instances are tested using the optimal models. Proposed system is capable of detecting the NGVCK viruses and MWORM with an accuracy of 100% using the meta opcode space of 25 features. A promising F1-score of 1.0 was gained and the results demonstrate the efficiency of the proposed metamorphic malware detector.
Keywords :
"Malware","Feature extraction","Markov processes","Hidden Markov models","Viruses (medical)","Redundancy","Predictive models"
Publisher :
ieee
Conference_Titel :
Contemporary Computing (IC3), 2015 Eighth International Conference on
Print_ISBN :
978-1-4673-7947-2
Type :
conf
DOI :
10.1109/IC3.2015.7346710
Filename :
7346710
Link To Document :
بازگشت