Windows malware detection system based on LSVC recommended hybrid features

dc.contributor.authorShiva Darshan, S.L.
dc.contributor.authorJaidhar, C.D.
dc.date.accessioned2026-02-05T09:30:02Z
dc.date.issued2019
dc.description.abstractTo combat exponentially evolved modern malware, an effective Malware Detection System and precise malware classification is highly essential. In this paper, the Linear Support Vector Classification (LSVC) recommended Hybrid Features based Malware Detection System (HF-MDS) has been proposed. It uses a combination of the static and dynamic features of the Portable Executable (PE) files as hybrid features to identify unknown malware. The application program interface calls invoked by the PE files during their execution along with their correspondent category are collected and considered as dynamic features from the PE file behavioural report produced by the Cuckoo Sandbox. The PE files’ header details such as optional header, disk operating system header, and file header are treated as static features. The LSVC is used as a feature selector to choose prominent static and dynamic features from their respective Original Feature Space. The features recommended by the LSVC are highly discriminative and used as final features for the classification process. Different sets of experiments were conducted using real-world malware samples to verify the combination of static and dynamic features, which encourage the classifier to attain high accuracy. The tenfold cross-validation experimental results demonstrate that the proposed HF-MDS is proficient in precisely detecting malware and benign PE files by attaining detection accuracy of 99.743% with sequential minimal optimization classifier consisting of hybrid features. © 2018, Springer-Verlag France SAS, part of Springer Nature.
dc.identifier.citationJournal of Computer Virology and Hacking Techniques, 2019, 15, 2, pp. 127-146
dc.identifier.urihttps://doi.org/10.1007/s11416-018-0327-9
dc.identifier.urihttps://idr.nitk.ac.in/handle/123456789/24549
dc.publisherSpringer-Verlag France 22, Rue de Palestro Paris 75002
dc.subjectApplication programs
dc.subjectClassification (of information)
dc.subjectComputer crime
dc.subjectDOS
dc.subjectMalware
dc.subjectOptimization
dc.subjectApplication program interfaces
dc.subjectCuckoo Sandbox
dc.subjectFeature selector
dc.subjectMalware classifications
dc.subjectN-grams
dc.subjectPortable Executable files
dc.subjectSequential minimal optimization
dc.subjectSupport vector classification
dc.subjectFeature extraction
dc.titleWindows malware detection system based on LSVC recommended hybrid features

Files

Collections