پدافند الکترونیکی و سایبری

پدافند الکترونیکی و سایبری

تشخیص بدافزار مبتنی بر الگوریتم فرا ابتکاری کرم شب­تاب و شبکه­ی یادگیری حافظه طولانی کوتاه­مدت

نوع مقاله : مقاله پژوهشی

نویسنده
استادیار ،دانشگاه گلستان ،گرگان گروه علوم کامپیوتر، گرگان، ایران
چکیده
تشخیص بدافزار به یکی از حوزههای تحقیقاتی مهم در چند سال اخیر تبدیل‌شده است. علیرغم کوششهایی که در این زمینه صورت گرفته است، همچنان امکان بهبود دقت مدلهای ارائه‌شده در تشخیص انواع مختلف بدافزار وجود دارد. در این مقاله، با تکیه‌بر به­کارگیری چهار الگوریتم فرا ابتکاری زنبورعسل، کرم شبتاب، رقابت استعماری و خفاش، تلاش برای تنظیم پارامترهای شبکههای یادگیری عمیق صورت گرفته است. دو شبکه­ی یاد گیر عمیق شامل شبکه­ی عصبی پیچشی و حافظه­ی طولانی کوتاهمدت با تعداد لایههای مختلف برای دستیابی به حداکثر دقت تشخیص مورداستفاده قرارگرفته‌اند. نتایج آزمایش نشان میدهد که در بهترین حالت، بهرهگیری از الگوریتم کرم شبتاب و شبکه­ی یاد گیر LSTM با 3 لایه، اندازه­ی دسته 40، اندازه­ی فیلتر 5*5 و تعداد دوره­ی 300 منجر به‌دقت 99.997% در تشخیص بدافزار می­شود که در مقایسه با سایر کارهای ارائه‌شده از برتری قابل‌ملاحظه‌ای برخوردار است. سایر پارامترهای ارزیابی کار آیی نیز مقادیر بسیار خوبی را نشان میدهند که این موضوع بیانگر برتری روش پیشنهادی نسبت به سایر کارهای مشابه است.
کلیدواژه‌ها
موضوعات

عنوان مقاله English

Malware Detection Based on Firefly Meta-Heuristic Algorithm and Long-Short-Term Memory Learning Network

نویسنده English

Aliakbar Tajari Siahmarzkooh
Assistant Professor, Golestan University, Gorgan, Iran
چکیده English

Malware detection has become one of the important research areas in recent years. Despite the efforts made in this field, it is still possible to improve the accuracy of the presented models in detecting different types of malware. In this paper, an attempt has been made to adjust the parameters of deep learning networks based on the use of four meta-heuristic algorithms including bee colony, firefly, imperialist competitive and bat algorithm. Two deep learning networks including Convolutional Neural Network (CNN) and Long-Short Term Memory (LSTM) with different number of layers have been used to achieve maximum detection accuracy. The experimental results show that in the best case, using the firefly algorithm and LSTM learning network with 3 layers, batch size 40, filter size 5*5 and number of periods 300 leads to an accuracy of 99.997% in malware detection, which is significantly superior compared to other presented works. Other performance evaluation parameters also show very good values, which indicates the superiority of the proposed method over other similar works.

کلیدواژه‌ها English

Malware detection Meta
heuristic algorithm Convolutional Neural Network Long
Short Term Memory Firefly algorithm
[4]    A. Thakkar, and R. Lohiya, “A review on machine learning and deep learning perspectives of IDS for IoT: recent updates, security issues, and challenges,” Archives of Computational Methods in Engineering, vol. 4, pp. 3211-3243, 2020.   https://doi.org/10.1007/s11831-020-09496-0.
[5]    R. Atefinia, and M. Ahmadi, “Network intrusion detection using multi-architectural modular deep neural network,” Journal of Supercomputing, vol. 4, pp. 3571–3593, 2021. https://doi.org/10.1007/s11227-020-03410-y.
[6]    S.I. Popoola, A. Bamidele, A. Ruth, M. Hammoudeh, A. Kelvin, and A. Aderemi, “SMOTE-DRNN: A deep learning algorithm for botnet detection in the Internet-of-Things networks,” Sensors, vol. 9, pp. 2851-2861, 2021. https://doi.org/10.3390/s21092985.
[7]    I. Idrissi, M. Boukabous, M. Azizi, O. Moussaoui, and H. El-Fadili, “Toward a deep  learning-based  intrusion  detection  system  for  IoT  against  botnet  attacks,” IAES  International  Journal  of Artificial Intelligence, vol. 1, pp. 110-122, 2021. DOI:10.11591/ijai.v10.i1.pp110-120.
[8]    M. Abdel-Basset, L. Abdel-Fatah, and A. Sangaiah, “Metaheuristic  algorithms:  A comprehensive review,” In Computational Intelligence for Multimedia Big Data on the Cloud with Engineering Applications, Academic press, pp. 185-231, 2018.  https://doi.org/10.1016/B978-0-12-813314-9.00010-4.
[9]    A.S. Bozkir, A.O. Cankaya, and M. Aydos, “Utilization and Comparison of Convolutional Neural Networks in Malware Recognition,” In Proceedings of the 27th Signal Processing and Communications Applications Conference (SIU), Sivas, Turkey, pp. 1–4, 2019. DOI10.1109/SIU.2019.8806511.
[10]    S.A. Roseline, S. Geetha, S. Kadry, and Y. Nam, “Intelligent Vision-based Malware Detection and Classification using Deep Random Forest Paradigm,” IEEE Access, vol. 8. pp. 206303–206324, 2020. DOI10.1109/ACCESS.2020.3036491.
[11]    M. Imran, M.T. Afzal, and M.A. Qadir, “Similarity-based malware classification using hidden Markov model,” In Proceedings of the Fourth International Conference on Cyber Security, Cyber Warfare, and Digital Forensic (CyberSec), Jakarta, Indonesia, pp. 129–134, 2015. DOI10.1109/CyberSec.2015.33.
[12]    K. Rieck, P. Trinius, C. Willems, and T. Holz, “Automatic analysis of malware behavior using machine learning,” Journal of Computer Security, vol. 19, pp. 639–668, 2011. DOI:10.3233/JCS-2010-0410.
[13]    S.O. Subairu, J. Alhassan, S. Misra, O. Abayomi-Alli, R. Ahuja, R. Damasevicius, and R. Maskeliunas, “An experimental approach to unravel effects of malware on system network interface,” In Lecture Notes in Electrical Engineering; Springer: Singapore, pp. 225–235, 2020.  https://doi.org/10.1007/978-981-15-0372-6_17.
[14]    H. Yan, H. Zhou, and H. Zhang, “Automatic malware classification via PRICoLBP,” Chinese Journal of Electronics, vol. 27, pp. 852–859, 2018. DOI:10.1049/cje.2018.05.001.
[15]    H. Naeem, F. Ullah, M.R. Naeem, S. Khalid, D. Vasan, S. Jabbar, and S. Saeed, “Malware detection in industrial internet of things based on hybrid image visualization and deep learning model,” Ad Hoc Networks, pp. 105-118, 2020. https://doi.org/10.1016/j.adhoc.2020.102154.
[16]    K. Han, B. Kang, E.G. Im, “Malware analysis using visualized image matrices,” The Scientific World Journal, 2014. doi: 10.1155/2014/132713. Epub 2014 Jul 16.
[17]    K. Kancherla, and S. Mukkamala, “Image visualization based malware detection,” In Proceedings of the 2013 IEEE Symposium on Computational Intelligence in Cyber Security (CICS), Singapore, pp. 40–44, 2013. DOI: 10.1109/CICYBS.2013.6597204.
[18]    L. Liu, and B. Wang, “Malware classification using gray-scale images and ensemble learning,” In Proceedings of the 3rd International Conference on Systems and Informatics (ICSAI), China, pp. 1018–1022, 2016. DOI:10.1109/ICSAI.2016.7811100.
[19]    D. Vasan, M. Alazab, S. Wassan, B. Safaei, and Q. Zheng, “Image-Based malware classification using ensemble of CNN architectures (IMCEC),” Computer Security, vol. 92, 101748, 2020. https://doi.org/10.1016/j.cose.2020.101748 .
[20]    A.F. Agarap, and F.J.H. Pepito, “Towards building an intelligent anti-malware system a deep learning approach using support vector machine (SVM) for malware classification,” arXiv 2017, arXiv:1801.00318, 2017.           
https://doi.org/10.48550/arXiv.1801.00318
.
[21]    S.A. Roseline, S. Geetha, S. Kadry, and Y. Nam, “Intelligent vision-based malware detection and classification using deep random forest paradigm,” IEEE Access, vol. 8, pp. 206303-206324., 2024, DOI: https://doi.org/10.1109/ACCESS.2020.3036491.
[22]    S. Tobiyama, Y. Yamaguchi, H. Shimada, T. Ikuse, and T. Yagi, “Malware detection with deep neural network using process behavior,” in: 2016 IEEE 40th annual computer software and applications conference (COMPSAC), vol. 2, pp. 577-582, 2016, DOI: 10.1109/COMPSAC.2016.151.
[23]    M. Akhtar, and T. Feng, “Detection of malware by deep learning as CNN-LSTM machine learning techniques in real time,” Symmetry, vol. 14, pp. 2308, 2022, DOI: https://doi.org/10.3390/sym14112308.
[24]    A. Al-Saaidah, M. Abualhaj, Q. Shambour, A. Abu-Shareha, L. Abualigah, S. Al-Khatib, and Y. Alraba’nah, “Enhancing malware detection performance: leveraging K-Nearest Neighbors with Firefly Optimization Algorithm,” Multimedia Tools and Applications, vol. 3, pp. 1-24, 2024, . DOI: https://doi.org/10.1007/s11042-024-18914-5.
[25]    R. Damaševičius, A. Venčkauskas, J. Toldinas, and S. Grigaliūnas, “Ensemble-based classification using neural networks and machine learning models for windows PE malware detection,” Electronics, vol. 10, pp. 485, 2021, DOI:     https://doi.org/10.3390/electronics10040485.
[26]    I. Pranaou, S. Christy, and T. Poovizhi, “Implementation of ML Algorithm for Spyware Detection System Using SVM with KNN Algorithm for Comparison of Accuracy,” in: 2024 9th International Conference on Applying New Technology in Green Buildings (ATiGB), pp. 1-5, 2024, DOI:  10.1109/ATiGB63471.2024.10717756.
[27]    Yerima, S. Sezer, and G. McWilliams, “Analysis of Bayesian classificationbased approaches for Android malware detection,” IET Information Security, vol. 8, pp. 25-36, 2014, DOI: https://doi.org/10.1049/iet-ifs.2013.0095.
[28]    M. Al-Andoli, S. Tan, K. Sim, C. Lim, and P. Goh, ”Parallel Deep Learning with a hybrid BP-PSO framework for feature extraction and malware classification,” Applied Soft Computing, vol. 131, pp. 109756, 2022, DOI: https://doi.org/10.1016/j.asoc.2022.109756.
[29]    S. Imtiaz, S. ur-Rehman, A. Javed, Z. Jalil, X. Liu, and W. Alnumay, “DeepAMD: Detection and identification of Android malware using high-efficient Deep Artificial Neural Network,” Future Generation computer systems, vol. 115, pp. 844-856, 2021, DOI: https://doi.org/10.1016/j.future.2020.10.008.
[30]    L. Suhuan, and H. Xiaojun, “Android malware detection based on logistic regression and XGBoost,” in: 2019 IEEE 10th International Conference on Software Engineering and Service Science (ICSESS), pp. 528-532, 2019, DOI:     10.1109/ICSESS47205.2019.9040851.
[31]    S. Kumar, and K. Panda, “SDIF-CNN: Stacking deep image features using fine-tuned convolution neural network models for real-world malware detection and classification,” Applied Soft Computing, vol. 146, 110676, 2023. https://doi.org/10.1016/j.asoc.2023.110676.
[32]    P. Yadava, N. Menonb, V. Ravic, S. Vishvanathand, and D.T. Phame, “A two-stage deep learning framework for image-based android malware detection and variant classification,” Computational Intelligence, vol. 38, pp. 1748–1771,     2020.  https://doi.org/10.1111/coin.12532
[33]    D. Karaboga, and B. Basturk, “Artificial bee colony (ABC) optimization algorithm for solving constrained optimization problems,” Advances in Soft Computing: Foundations of Fuzzy Logic and Soft Computing, LNCS: 789-798, Springer, Berlin, 2007. https://doi.org/10.1007/978-3-540-72950-1_77.
[34]    M. Abualhaj, M. Al-Zyoud, A. Alsaaideh, A. Abu-Sharcha, and S. Al-Khatib, "Enhancing Malware Detection through Self-Union Feature Selection Using Firefly Algorithm with Random Forest Classification," International Journal of Intelligent Engineering & Systems, vol. 4, pp. 376-389, 2024. DOI: 10.22266/ijies2024.0831.29.
[35]    A. Kaveh, "Imperialist competitive algorithm," Advances in Metaheuristic Algorithms for Optimal Design of Structures, pp. 353-373, 2017. https://en.wikipedia.org/wiki/Imperialist_competitive_algorithm.
[36]    R. Penmasta, S. Mallidi, K. Jhansi, and D. Latha, "Bat optimization algorithm for wrapper-based feature selection and performance improvement of android malware detection," IET Networks, vol. 3, 2021. DOI: 10.1049/ntw2.12022.
دوره 13، شماره 3 - شماره پیاپی 51
پاییز
پاییز 1404
صفحه 71-85

  • تاریخ دریافت 08 تیر 1404
  • تاریخ بازنگری 23 شهریور 1404
  • تاریخ پذیرش 22 مهر 1404
  • تاریخ انتشار 01 آبان 1404