Electronic and Cyber Defense

Electronic and Cyber Defense

Host-based Anomaly Malware Detection Using Deep Learning

Document Type : Original Article

Authors
1 Master's degree, University of Zanjan, Zanjan, Iran
2 Assistant Professor, University of Zanjan, Zanjan, Iran
Abstract
Windows operating system, as the most widely used operating system of desktop computers, is still one of the main targets of malware writers. For this reason, many researches have recently been conducted to detect Windows malware. Due to the emergence and application of deep learning, although researchers have been able to use it to detect Windows malware, but there are still various challenges such as the detection of new and zero-day malwares and lack of evolution of processes of the feature engineering that increase the false positive rate. Currently, deep learning based malware detection approaches are either two class or multi classes, which fail to detect anomaly and zero-day malware. in this research, in addition to using a combination of various features of static and dynamic including file, registry, network, calls and PE import names, we also have increased the number and variety of normal datasets using the conditional tabular generative adversarial model for more accurate training, then we made it possible to detect anomalies and zero-day malware by presenting the deep approach of one-class generative adversarial network model. The result of the research includes a false alarm rate of approximately 1% with a high detection rate of 99% that compared to similar methods, indicates the success of the proposed method.
Keywords
Subjects

Smiley face

https://creativecommons.org/licenses/by/4.0/

[1] Chalapathy, R. and S. Chawla, Deep learning for anomaly detection: A survey. arXiv preprint arXiv:1901.03407, 2019.
[2] Tajoddin, A. and M. Abadi, RAMD: registry-based anomaly malware detection using one-class ensemble classifiers. Applied Intelligence, 2019. 49(7): p. 2641-2658.
[3] Liu, J., et al. FENOC: an ensemble one-class learning framework for malware detection. in 2013 Ninth International Conference on Computational Intelligence and Security. 2013. IEEE.
[4] Tang, A., S. Sethumadhavan, and S.J. Stolfo. Unsupervised anomaly-based malware detection using hardware features. in Research in Attacks, Intrusions and Defenses: 17th International Symposium, RAID 2014, Gothenburg, Sweden, September 17-19, 2014. Proceedings 17. 2014. Springer.
[5] Miao, Q., et al., Malware detection using bilayer behavior abstraction and improved one-class support vector machines. International Journal of Information Security, 2016. 15: p. 361-379.
[6] Yousefi-Azar, M., et al. Autoencoder-based feature learning for cyber security applications. in 2017 International joint conference on neural networks (IJCNN). 2017. IEEE.
[7] Kim, J.-Y., S.-J. Bu, and S.-B. Cho. Malware detection using deep transferred generative adversarial networks. in Neural Information Processing: 24th International Conference, ICONIP 2017, Guangzhou, China, November 14-18, 2017, Proceedings, Part I 24. 2017. Springer.
[8] Kim, J.-Y., S.-J. Bu, and S.-B. Cho, Zero-day malware detection using transferred generative adversarial networks based on deep autoencoders. Information Sciences, 2018. 460: p. 83-102.
[9] Ijaz, M., M.H. Durad, and M. Ismail. Static and dynamic malware analysis using machine learning. in 2019 16th International bhurban conference on applied sciences and technology (IBCAST). 2019. IEEE.
Volume 12, Issue 4 - Serial Number 48
Winter
Winter 2025
Pages 45-54

  • Receive Date 15 October 2024
  • Revise Date 03 December 2024
  • Accept Date 12 January 2025
  • Publish Date 20 January 2025