作者: S. L. Shiva Darshan , C. D. Jaidhar
DOI: 10.1007/S13042-019-00978-7
关键词: Classifier (UML) 、 Random forest 、 Source code 、 Computational intelligence 、 Data mining 、 Portable Executable 、 Decision tree 、 Computer science 、 Malware 、 Feature selection
摘要: The emergence of advanced malware is a serious threat to information security. A prominent technique that identifies sophisticated should consider the runtime behaviour source file detect malicious intent. Although behaviour-based detection substantial improvement over traditional signature-based technique, current employs code obfuscation techniques elude detection. This paper presents Hybrid Features-based system (HFMDS) integrates static and dynamic features portable executable (PE) files discern malware. HFMDS trained with advised by filter-based feature selection (FST). ability proposed has evaluated random forest (RF) classifier considering two different datasets consist real-world Windows samples. In-depth analysis carried out determine optimal number decision trees (DTs) required RF achieve consistent accuracy. Besides, four popular FSTs performance also analyzed which FST recommends best features. From experimental analysis, we can infer increasing DTs after 160 within does not make significant difference in attaining better