跳到主要导航 跳到搜索 跳到主要内容

From big data to knowledge: A spatio-temporal approach to malware detection

  • Weixuan Mao
  • , Zhongmin Cai
  • , Yuan Yang
  • , Xiaohong Shi
  • , Xiaohong Guan
  • Xi'an Jiaotong University
  • National Computer Network Emergency Response Technical Team/Coordination Center of China
  • Beijing Qihoo Technology Co. Ltd.
  • Tsinghua University

科研成果: 期刊稿件文章同行评审

7 引用 (Scopus)

摘要

The deployment of endpoint protection has been gradually migrated from individual clients to remote cloud servers, which is termed as cloud based security service. The new paradigm of security defense produces a large amount of data and log files, and motivates data-driven techniques for detecting malicious software. This paper conducts an empirical study on the log of a real cloud based security service to characterize the occurrence of executable files in end hosts, which concerns 124,782 benign and 113,305 malicious executable files occurred in 165,549,417 end hosts. The end hosts and the timestamps that an executable file occurs in provide insights into the distribution of software in wild from spatial and temporal perspectives, respectively. Meanwhile, we investigate the strategies behind the characterizations, and observe the preferential attachment process and the periodicity of file occurrence in end hosts. The observed different occurrence patterns of benign and malicious files in end hosts inspire us a new scalable approach to malware detection. We learn from the characterizations that, the associated files shared more spatial and temporal information in common are more likely to be same in their labels, either benign or malicious. Thus, we devise a graph based semi-supervised learning algorithm for real-time malware detection by taking into account the spatio-temporal information of the distribution of executable files. Experimental results demonstrate that our approach increases the performance on malware detection by 14.7% over previous techniques on average.

源语言英语
页(从-至)167-183
页数17
期刊Computers and Security
74
DOI
出版状态已出版 - 5月 2018

学术指纹

探究 'From big data to knowledge: A spatio-temporal approach to malware detection' 的科研主题。它们共同构成独一无二的指纹。

引用此