TY - GEN
T1 - Malware detection via API calls, topic models and machine learning
AU - Sundarkumar, G. Ganesh
AU - Ravi, Vadlamani
AU - Nwogu, Ifeoma
AU - Govindaraju, Venu
N1 - Publisher Copyright:
© 2015 IEEE.
PY - 2015/10/7
Y1 - 2015/10/7
N2 - Dissemination of malicious code, also known as malware, poses severe challenges to cyber security. Malware authors embed software in seemingly innocuous executables, unknown to a user. The malware subsequently interacts with security-critical OS resources on the host system or network, in order to destroy their information or to gather sensitive information such as passwords and credit card numbers. Malware authors typically use Application Programming Interface (API) calls to perpetrate these crimes. We present a model that uses text mining and topic modeling to detect malware, based on the types of API call sequences. We evaluated our technique on two publicly available datasets. We observed that Decision Tree and Support Vector Machine yielded significant results. We performed t-test with respect to sensitivity for the two models and found that statistically there is no significant difference between these models. We recommend Decision Tree as it yields 'if-then' rules, which could be used as an early warning expert system.
AB - Dissemination of malicious code, also known as malware, poses severe challenges to cyber security. Malware authors embed software in seemingly innocuous executables, unknown to a user. The malware subsequently interacts with security-critical OS resources on the host system or network, in order to destroy their information or to gather sensitive information such as passwords and credit card numbers. Malware authors typically use Application Programming Interface (API) calls to perpetrate these crimes. We present a model that uses text mining and topic modeling to detect malware, based on the types of API call sequences. We evaluated our technique on two publicly available datasets. We observed that Decision Tree and Support Vector Machine yielded significant results. We performed t-test with respect to sensitivity for the two models and found that statistically there is no significant difference between these models. We recommend Decision Tree as it yields 'if-then' rules, which could be used as an early warning expert system.
UR - https://www.scopus.com/pages/publications/84952766034
U2 - 10.1109/CoASE.2015.7294263
DO - 10.1109/CoASE.2015.7294263
M3 - Conference contribution
AN - SCOPUS:84952766034
T3 - IEEE International Conference on Automation Science and Engineering
SP - 1212
EP - 1217
BT - 2015 IEEE Conference on Automation Science and Engineering
PB - IEEE Computer Society
T2 - 11th IEEE International Conference on Automation Science and Engineering, CASE 2015
Y2 - 24 August 2015 through 28 August 2015
ER -