4.5 Article

Survey of machine learning techniques for malware analysis

期刊

COMPUTERS & SECURITY
卷 81, 期 -, 页码 123-147

出版社

ELSEVIER ADVANCED TECHNOLOGY
DOI: 10.1016/j.cose.2018.11.001

关键词

Portable executable; Malware analysis; Machine learning; Benchmark; Malware analysis economics

资金

  1. Italian Presidency of Ministry Council
  2. Laboratorio Nazionale of Cyber Security of the CINI (Consorzio Interuniversitario Nazionale Informatica)
  3. EPSRC [EP/K003968/1, EP/R007268/1] Funding Source: UKRI

向作者/读者索取更多资源

Coping with malware is getting more and more challenging, given their relentless growth in complexity and volume. One of the most common approaches in literature is using machine learning techniques, to automatically learn models and patterns behind such complexity, and to develop technologies to keep pace with malware evolution. This survey aims at providing an overview on the way machine learning has been used so far in the context of malware analysis in Windows environments, i.e. for the analysis of Portable Executables. We systematize surveyed papers according to their objectives (i.e., the expected output), what information about malware they specifically use (i.e., the features), and what machine learning techniques they employ (i.e., what algorithm is used to process the input and produce the output). We also outline a number of issues and challenges, including those concerning the used datasets, and identify the main current topical trends and how to possibly advance them. In particular, we introduce the novel concept of malware analysis economics, regarding the study of existing trade-offs among key metrics, such as analysis accuracy and economical costs. (C) 2018 Elsevier Ltd. All rights reserved.

作者

我是这篇论文的作者
点击您的名字以认领此论文并将其添加到您的个人资料中。

评论

主要评分

4.5
评分不足

次要评分

新颖性
-
重要性
-
科学严谨性
-
评价这篇论文

推荐

暂无数据
暂无数据