Linux Malware Behavior Description

A major threat to system’s security is malware infections, which cause financial and image losses to corporate and endusers, thus motivating the development of malware detectors. In this scenario, Machine Learning (ML) has been demonstrated to be a powerful technique to develop classifiers able to d...

Full description

Saved in:
Bibliographic Details
Main Authors: Galante, Lucas, Geus, Paulo de, Botacin, Marcus
Format: Online
Language:Portuguese
Published: Universidade Estadual de Campinas 2019
Subjects:
Online Access:https://econtents.sbu.unicamp.br/eventos/index.php/pibic/article/view/2426
Tags: Add Tag
No Tags, Be the first to tag this record!
Description
Summary:A major threat to system’s security is malware infections, which cause financial and image losses to corporate and endusers, thus motivating the development of malware detectors. In this scenario, Machine Learning (ML) has been demonstrated to be a powerful technique to develop classifiers able to distinguish malware from goodware samples. However, many ML research work on malware detection focus only on the final detection accuracy rate and overlook other important aspects of classifier’s implementation and evaluation, such as feature extraction and parameter selection. In this project, we shed light to these aspects to highlight the challenges and drawbacks of ML-based malware classifiers development. We discovered that (i) dynamic features outperforms static features; (ii) Discrete-bounded features present smaller accuracy variance; (iii) Datasets presenting distinct characteristics impose generalization challenges to ML models; and (iv) Feature analysis can be used as feedback information for malware detection and infection prevention.
ISSN:2596-1969