Logo image
Behavioral Malware Detection using a Language Model Classifier Trained on sys2vec Embeddings
Conference proceeding   Open access

Behavioral Malware Detection using a Language Model Classifier Trained on sys2vec Embeddings

John Carter, Spiros Mancoridis, Pavlos Protopapas and Erick Galinkin
Proceedings of the 57th Hawaii International Conference on System Sciences, pp 7582-7591
01 Jan 2024
url
https://doi.org/10.24251/HICSS.2024.911View
Published, Version of Record (VoR) Open CC BY-NC-ND V4.0

Abstract

Computer Science, Information Systems Computer Science, Interdisciplinary Applications Computer Science, Software Engineering Science & Technology Computer Science Technology
Behavioral malware detection is an effective way to detect ever-changing malware. Often, kernel-level system calls are collected on device and then processed and fed to machine learning models. In this work, we show that using simple natural language processing (NLP) techniques on system calls, such as a bag-of-n-grams model, coupled with shallow machine learning classifiers, are not as useful for stealthier malware. In contrast, training a Word2Vec-like model, which we call sys2vec, on the system call traces and feeding the resulting embeddings to a language model classifier provides consistently better results. We evaluate and compare the two classifiers using Area Under the Receiver Operating Characteristic Curve (AUC) and the True Positive Rate (TPR) at an acceptable False Positive Rate (FPR). We then discuss how this work can be further expanded in the language model space going forward.

Metrics

Details

InCites Highlights

Data related to this publication, from InCites Benchmarking & Analytics tool:

Collaboration types
Domestic collaboration
Web of Science research areas
Computer Science, Information Systems
Computer Science, Interdisciplinary Applications
Computer Science, Software Engineering
Logo image