Computer activity learning from system call time series

11/06/2017
by   Curt Hastings, et al.
0

Using a previously introduced similarity function for the stream of system calls generated by a computer, we engineer a program-in-execution classifier using deep learning methods. Tested on malware classification, it significantly outperforms current state of the art. We provide a series of performance measures and tests to demonstrate the capabilities, including measurements from production use. We show how the system scales linearly with the number of endpoints. With the system we estimate the total number of malware families created over the last 10 years as 3450, in line with reasonable economic constraints. The more limited rate for new malware families than previously acknowledged implies that machine learning malware classifiers risk being tested on their training set; we achieve F1 = 0.995 in a test carefully designed to mitigate this risk.

READ FULL TEXT
research
05/01/2023

Classification and Online Clustering of Zero-Day Malware

A large amount of new malware is constantly being generated, which must ...
research
02/28/2021

Virus-MNIST: A Benchmark Malware Dataset

The short note presents an image classification dataset consisting of 10...
research
11/18/2021

Enhancing the Insertion of NOP Instructions to Obfuscate Malware via Deep Reinforcement Learning

Current state-of-the-art research for tackling the problem of malware de...
research
05/30/2019

An Efficient Detection of Malware by Naive Bayes Classifier Using GPGPU

Due to continuous increase in the number of malware (according to AV-Tes...
research
02/08/2023

Continuous Learning for Android Malware Detection

Machine learning methods can detect Android malware with very high accur...
research
06/15/2020

A Survey of Machine Learning Methods and Challenges for Windows Malware Classification

Malware classification is a difficult problem, to which machine learning...
research
07/16/2018

Time Series Deinterleaving of DNS Traffic

Stream deinterleaving is an important problem with various applications ...

Please sign up or login with your details

Forgot password? Click here to reset