首页> 外文会议>IEEE International Conference on Industry 4.0, Artificial Intelligence, and Communications Technology >Detection of Malware using Machine Learning based on Operation Code Frequency
【24h】

Detection of Malware using Machine Learning based on Operation Code Frequency

机译:基于操作码频率的机器学习恶意软件检测

获取原文
获取外文期刊封面目录资料

摘要

One of the many methods for identifying malware is to disassemble the malware files and obtain the opcodes from them. Since malware have predominantly been found to contain specific opcode sequences in them, the presence of the same sequences in any incoming file or network content can be taken up as a possible malware identification scheme. Malware detection systems help us to understand more about ways on how malware attack a system and how it can be prevented. The proposed method analyses malware executable files with the help of opcode information by converting the incoming executable files to assembly language thereby extracting opcode information (opcode count) from the same. The opcode count is then converted into opcode frequency which is stored in a CSV file format. The CSV file is passed to various machine learning algorithms like Decision Tree Classifier, Random Forest Classifier and Naive Bayes Classifier. Random Forest Classifier produced the highest accuracy and hence the same model was used to predict whether an incoming file contains a potential malware or not.
机译:识别恶意软件的众多方法之一是反汇编恶意软件文件并从中获取操作码。由于发现恶意软件中主要包含特定的操作码序列,因此任何传入文件或网络内容中存在相同的序列都可能被视为恶意软件识别方案。恶意软件检测系统帮助我们更多地了解恶意软件如何攻击系统以及如何预防。该方法通过将输入的可执行文件转换为汇编语言,利用操作码信息分析恶意软件可执行文件,从而从中提取操作码信息(操作码计数)。然后将操作码计数转换为以CSV文件格式存储的操作码频率。CSV文件被传递给各种机器学习算法,如决策树分类器、随机森林分类器和朴素贝叶斯分类器。随机森林分类器产生了最高的精确度,因此使用相同的模型来预测传入文件是否包含潜在的恶意软件。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号