Sciweavers

CSDA
2008

Detection of unknown computer worms based on behavioral classification of the host

13 years 11 months ago
Detection of unknown computer worms based on behavioral classification of the host
Machine learning techniques are widely used in many fields. One of the applications of machine learning in the field of the information security is classification of a computer behavior into malicious and benign. Anti viruses consisting on signature-based methods are helpless against new (unknown) computer worms. This paper focuses on the feasibility of accurately detecting unknown worm activity in individual computers while minimizing the required set of features collected from the monitored computer. A comprehensive experiment for testing the feasibility of detecting unknown computer worms, employing several computer configurations, background applications, and user activity, was performed. During the experiments 323 computer features were monitored by an agent that was developed. Four feature selection methods were used to reduce the amount of features and four learning algorithms were applied on the resulting feature subsets. The evaluation results suggests that using classificati...
Robert Moskovitch, Yuval Elovici, Lior Rokach
Added 10 Dec 2010
Updated 10 Dec 2010
Type Journal
Year 2008
Where CSDA
Authors Robert Moskovitch, Yuval Elovici, Lior Rokach
Comments (0)