Malware detection using augmented naive Bayes with domain knowledge and under presence of class noise. (1st January 2014)
- Record Type:
- Journal Article
- Title:
- Malware detection using augmented naive Bayes with domain knowledge and under presence of class noise. (1st January 2014)
- Main Title:
- Malware detection using augmented naive Bayes with domain knowledge and under presence of class noise
- Authors:
- Ismail, Ismahani
Marsono, Muhammad Nadzir
Nor, Sulaiman Mohd - Abstract:
- Malicious software (malware) attacks on the internet are on the rise in frequency and sophistication. Malware detection based on its content can detect malware more accurate because it relies on screening the payload for known malware signatures. New malware variants still exhibit prevalent contents that can be detected by looking at fixed substrings especially when using n -grams and machine learning technique. This paper focuses on detecting malware based on content classification technique that is augmented with domain knowledge (Snort signatures) to abridge features set and improve detection accuracy. Using 15 days dataset, the generated naive Bayes model with domain knowledge using the most descriptive 91, 127 features shows the lowest false negative (around 2%). However, the presence of class noise has a significant impact on the results, even for machine learning technique augmented with domain knowledge.
- Is Part Of:
- International journal of information and computer security. Volume 6:Number 2(2014)
- Journal:
- International journal of information and computer security
- Issue:
- Volume 6:Number 2(2014)
- Issue Display:
- Volume 6, Issue 2 (2014)
- Year:
- 2014
- Volume:
- 6
- Issue:
- 2
- Issue Sort Value:
- 2014-0006-0002-0000
- Page Start:
- 179
- Page End:
- 197
- Publication Date:
- 2014-01-01
- Subjects:
- malware detection -- feature classification -- class noise -- domain knowledge
Computer security -- Periodicals
Information systems management -- Security measures -- Periodicals
Computer networks -- Security measures -- Periodicals
Information technology -- Security measures -- Periodicals
005.805 - Journal URLs:
- http://www.inderscience.com/browse/index.php?journalCODE=ijics ↗
http://www.inderscience.com/ ↗ - Languages:
- English
- ISSNs:
- 1744-1765
- Deposit Type:
- Legaldeposit
- View Content:
- Available online (eLD content is only available in our Reading Rooms) ↗
- Physical Locations:
- British Library DSC - BLDSS-3PM
British Library STI - ELD Digital store - Ingest File:
- 8682.xml