Using a Subtractive Center Behavioral Model to Detect Malware

dc.authoridTANRIOVER, O. Ozgur/0000-0002-1052-6124
dc.authoridSAMET, REFIK/0000-0001-8720-6834
dc.authoridASLAN, Omer/0000-0003-0737-1966
dc.authoridTanriover, O. Ozgur/0000-0003-0833-3494
dc.contributor.authorAslan, Omer
dc.contributor.authorSamet, Refik
dc.contributor.authorTanriover, Omer Ozgur
dc.date.accessioned2024-12-24T19:29:48Z
dc.date.available2024-12-24T19:29:48Z
dc.date.issued2020
dc.departmentSiirt Üniversitesi
dc.description.abstractIn recent years, malware has evolved by using different obfuscation techniques; due to this evolution, the detection of malware has become problematic. Signature-based and traditional behavior-based malware detectors cannot effectively detect this new generation of malware. This paper proposes a subtractive center behavior model (SCBM) to create a malware dataset that captures semantically related behaviors from sample programs. In the proposed model, system paths, where malware behaviors are performed, and malware behaviors themselves are taken into consideration. This way malicious behavior patterns are differentiated from benign behavior patterns. Features that could not exceed the specified score are removed from the dataset. The datasets created using the proposed model contain far fewer features than the datasets created by n-gram and other models that have been used in other studies. The proposed model can handle both known and unknown malware, and the obtained detection rate and accuracy of the proposed model are higher than those of the known models. To show the effectiveness of the proposed model, 2 datasets with score and without score are created by using SCBM. In total, 6700 malware samples and 3000 benign samples are tested. The results are compared with those derived from n-gram and models from other studies in the literature. The test results show that, by combining the proposed model with an appropriate machine learning algorithm, the detection rate, false positive rate, and accuracy are measured as 99.9%, 0.2%, and 99.8%, respectively.
dc.identifier.doi10.1155/2020/7501894
dc.identifier.issn1939-0114
dc.identifier.issn1939-0122
dc.identifier.scopus2-s2.0-85081155451
dc.identifier.scopusqualityN/A
dc.identifier.urihttps://doi.org/10.1155/2020/7501894
dc.identifier.urihttps://hdl.handle.net/20.500.12604/7233
dc.identifier.volume2020
dc.identifier.wosWOS:000522223400002
dc.identifier.wosqualityQ4
dc.indekslendigikaynakWeb of Science
dc.indekslendigikaynakScopus
dc.language.isoen
dc.publisherWiley-Hindawi
dc.relation.ispartofSecurity and Communication Networks
dc.relation.publicationcategoryMakale - Uluslararası Hakemli Dergi - Kurum Öğretim Elemanı
dc.rightsinfo:eu-repo/semantics/openAccess
dc.snmzKA_20241222
dc.titleUsing a Subtractive Center Behavioral Model to Detect Malware
dc.typeArticle

Dosyalar