ASSCA: API sequence and statistics features combined architecture for malware detection

In this paper, a new deep learning and machine learning combined model is proposed for malware behavior analysis. One part of it analyzes the dependency relation in API (Application Programming Interface) call sequence at the functional level, and extracts features for random forest to learn and cla...

Ausführliche Beschreibung

Gespeichert in:
Bibliographische Detailangaben
Veröffentlicht in:Computer networks (Amsterdam, Netherlands : 1999) Netherlands : 1999), 2019-07, Vol.157, p.99-111
Hauptverfasser: Xiaofeng, Lu, Fangshuo, Jiang, Xiao, Zhou, Shengwei, Yi, Jing, Sha, Lio, Pietro
Format: Artikel
Sprache:eng
Schlagworte:
Online-Zugang:Volltext
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
Beschreibung
Zusammenfassung:In this paper, a new deep learning and machine learning combined model is proposed for malware behavior analysis. One part of it analyzes the dependency relation in API (Application Programming Interface) call sequence at the functional level, and extracts features for random forest to learn and classify. The other part employs a bidirectional residual neural network to study the API sequence and discover malware with redundant information preprocessing. In the API call sequence, future information is much more important for conjecturing the semantic of the current API call. We conducted experiments on a malware dataset. The experiment results show that both methods can effectively detect malwares. However, the combined framework has better classification performance. The classification accuracy of the combined malware detection architecture is 0.967.
ISSN:1389-1286
1872-7069
DOI:10.1016/j.comnet.2019.04.007