作者: Nada Alruhaily , Tom Chothia , Behzad Bordbar
DOI: 10.1007/978-3-319-93354-2_3
关键词: Behavioural analysis 、 Malware 、 Artificial intelligence 、 Computer science 、 Detection rate 、 Machine learning
摘要: Machine learning-based malware detection systems have been widely suggested and used as a replacement for signature-based methods. Such shown that they can provide high rate when recognising non-previously seen samples. However, classifying based on their behavioural features, some new go undetected, resulting in misclassification. Our aim is to gain more understanding of the underlying causes misclassification; this will help develop robust systems. Towards objective, several questions addressed paper: Does misclassification increase over period time? Do changes affect classification occur at level families, where all instances belong certain families are hard detect? Alternatively, such be traced back variants instead families? Also, does removing distinct API functions only by malware? As technique could writers evade detection. experiments showed behaviour mostly due across did not behave expected. It also machine maintain even case trying using functions, which uniquely malware.