Jiachen Liu, Jianfeng Song, Qiguang Miao, Ying Cao
{"title":"FENOC: An Ensemble One-Class Learning Framework for Malware Detection","authors":"Jiachen Liu, Jianfeng Song, Qiguang Miao, Ying Cao","doi":"10.1109/CIS.2013.116","DOIUrl":null,"url":null,"abstract":"Nowadays, machine learning based methods are among the most popular ones for malware detection. However, most of the previous works use a single type of features, dynamic or static, and take them to build a binary classification model. These methods have limited ability to depict characteristic malware behaviors and suffer from insufficiently sampled benign samples and extremely imbalanced training dataset. In this paper, we present FENOC, an ensemble one-class learning framework for malware detection. FENOC uses hybrid features from multiple semantic layers to ensure comprehensive insights of analyzed programs, and constructs detection model via CosTOC (Cost-sensitive Twin One-class Classifier), a novel one-class learning algorithm, which uses a pair of one-class classifiers to describe malware class and benign program class respectively. CosTOC is more flexible and robust when handling malware detection problems, which is imbalanced and need low false positive rate. Meanwhile, a random subspace ensemble method is used to enhance the generalization ability of CosTOC. Experimental results show that to detect unknown malware, FENOC has a higher detection rate and a lower false positive rate, especially in the situations that training datasets are imbalanced.","PeriodicalId":294223,"journal":{"name":"2013 Ninth International Conference on Computational Intelligence and Security","volume":"60 8","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2013-12-14","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"10","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2013 Ninth International Conference on Computational Intelligence and Security","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/CIS.2013.116","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 10
Abstract
Nowadays, machine learning based methods are among the most popular ones for malware detection. However, most of the previous works use a single type of features, dynamic or static, and take them to build a binary classification model. These methods have limited ability to depict characteristic malware behaviors and suffer from insufficiently sampled benign samples and extremely imbalanced training dataset. In this paper, we present FENOC, an ensemble one-class learning framework for malware detection. FENOC uses hybrid features from multiple semantic layers to ensure comprehensive insights of analyzed programs, and constructs detection model via CosTOC (Cost-sensitive Twin One-class Classifier), a novel one-class learning algorithm, which uses a pair of one-class classifiers to describe malware class and benign program class respectively. CosTOC is more flexible and robust when handling malware detection problems, which is imbalanced and need low false positive rate. Meanwhile, a random subspace ensemble method is used to enhance the generalization ability of CosTOC. Experimental results show that to detect unknown malware, FENOC has a higher detection rate and a lower false positive rate, especially in the situations that training datasets are imbalanced.