Risk-Based System-Call Sequence Grouping Method for Malware Intrusion Detection

Tolvinas Vyšniūnas,Dainius Čeponis,Nikolaj Goranin,Antanas Čenys
DOI: https://doi.org/10.3390/electronics13010206
IF: 2.9
2024-01-03
Electronics
Abstract:Malware intrusion is a serious threat to cybersecurity; that is why new and innovative methods are constantly being developed to detect and prevent it. This research focuses on malware intrusion detection through the usage of system calls and machine learning. An effective and clearly described system-call grouping method could increase the various metrics of machine learning methods, thereby improving the malware detection rate in host-based intrusion-detection systems. In this article, a risk-based system-call sequence grouping method is proposed that assigns riskiness values from low to high based on function risk value. The application of the newly proposed grouping method improved classification accuracy by 23.4% and 7.6% with the SVM and DT methods, respectively, compared to previous results obtained on the same methods and data. The results suggest the use of lightweight machine learning methods for malware attack can ensure detection accuracy comparable to deep learning methods.
engineering, electrical & electronic,computer science, information systems,physics, applied
What problem does this paper attempt to address?