A System-call Behavior Language System for Malware Detection Using A Sensitivity-based LSTM Model

18Citations
Citations of this article
16Readers
Mendeley users who have this article in their library.
Get full text

Abstract

With the increasing number and variety of malware, it is imperative to design behavior analysis system to detect them. In this paper, we propose a sensitivity-based LSTM model to design a System-call Behavioral Language (SBL) system for malware detection. The behavior of software can be represented by a System-call sequence. Each System-call has different sensitivity which is related with the resource it handles and so should be paid different attention. The model we designed in SBL system consists of two parts: behavior language learning and sensitivity-based attention calculation. Our model obtains the AUC values of 0.99 on the test dataset, and 0.93 on the unknown dataset which is 0.15 higher than KNN and 0.02 higher than Random Forest. Especially, our model achieves 78% specificity on the unknown attack dataset, while the classic language model can only reach 66%.

Cite

CITATION STYLE

APA

Xie, W., Xu, S., Zou, S., & Xi, J. (2020). A System-call Behavior Language System for Malware Detection Using A Sensitivity-based LSTM Model. In ACM International Conference Proceeding Series (pp. 112–118). Association for Computing Machinery. https://doi.org/10.1145/3403746.3403914

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free