Next Article in Journal
Recent Advances and Applications of Rapid Microbial Assessment from a Food Safety Perspective
Next Article in Special Issue
A Method for Detecting LDoS Attacks in SDWSN Based on Compressed Hilbert–Huang Transform and Convolutional Neural Networks
Previous Article in Journal
Effects of Thermal Gradients in High-Temperature Ultrasonic Non-Destructive Tests
Previous Article in Special Issue
CANon: Lightweight and Practical Cyber-Attack Detection for Automotive Controller Area Networks
 
 
Font Type:
Arial Georgia Verdana
Font Size:
Aa Aa Aa
Line Spacing:
Column Width:
Background:
Article

Zero-Day Malware Detection and Effective Malware Analysis Using Shapley Ensemble Boosting and Bagging Approach

School of Computer Science and Engineering, Vellore Institute of Technology, Chennai Campus, Chennai 600127, Tamil Nadu, India
*
Author to whom correspondence should be addressed.
Sensors 2022, 22(7), 2798; https://doi.org/10.3390/s22072798
Submission received: 15 February 2022 / Revised: 28 March 2022 / Accepted: 28 March 2022 / Published: 6 April 2022
(This article belongs to the Collection Cyber Situational Awareness in Computer Networks)

Abstract

Software products from all vendors have vulnerabilities that can cause a security concern. Malware is used as a prime exploitation tool to exploit these vulnerabilities. Machine learning (ML) methods are efficient in detecting malware and are state-of-art. The effectiveness of ML models can be augmented by reducing false negatives and false positives. In this paper, the performance of bagging and boosting machine learning models is enhanced by reducing misclassification. Shapley values of features are a true representation of the amount of contribution of features and help detect top features for any prediction by the ML model. Shapley values are transformed to probability scale to correlate with a prediction value of ML model and to detect top features for any prediction by a trained ML model. The trend of top features derived from false negative and false positive predictions by a trained ML model can be used for making inductive rules. In this work, the best performing ML model in bagging and boosting is determined by the accuracy and confusion matrix on three malware datasets from three different periods. The best performing ML model is used to make effective inductive rules using waterfall plots based on the probability scale of features. This work helps improve cyber security scenarios by effective detection of false-negative zero-day malware.
Keywords: machine learning; computer security; artificial intelligence; boosting; bagging; cyber security; zero-day vulnerability; zero-day malware detection; Shapley value machine learning; computer security; artificial intelligence; boosting; bagging; cyber security; zero-day vulnerability; zero-day malware detection; Shapley value

Share and Cite

MDPI and ACS Style

Kumar, R.; Subbiah, G. Zero-Day Malware Detection and Effective Malware Analysis Using Shapley Ensemble Boosting and Bagging Approach. Sensors 2022, 22, 2798. https://doi.org/10.3390/s22072798

AMA Style

Kumar R, Subbiah G. Zero-Day Malware Detection and Effective Malware Analysis Using Shapley Ensemble Boosting and Bagging Approach. Sensors. 2022; 22(7):2798. https://doi.org/10.3390/s22072798

Chicago/Turabian Style

Kumar, Rajesh, and Geetha Subbiah. 2022. "Zero-Day Malware Detection and Effective Malware Analysis Using Shapley Ensemble Boosting and Bagging Approach" Sensors 22, no. 7: 2798. https://doi.org/10.3390/s22072798

APA Style

Kumar, R., & Subbiah, G. (2022). Zero-Day Malware Detection and Effective Malware Analysis Using Shapley Ensemble Boosting and Bagging Approach. Sensors, 22(7), 2798. https://doi.org/10.3390/s22072798

Note that from the first issue of 2016, this journal uses article numbers instead of page numbers. See further details here.

Article Metrics

Back to TopTop