20
Views
0
CrossRef citations to date
0
Altmetric
Research Article

Applying unsupervised system-call based software security techniques for anomaly detection

, &
 

Abstract

System call analysis is a technique intended for detecting malware. The above method helps in achieving better detection accuracy. Thus, machine learning (ML) techniques are used for this evaluation. This paper discusses unsupervised ML techniques to detect malware. Our proposed detector monitors the software and marks them anomalous or benign based on their behavior. Experimental results provide performance statistics based on the true positive rate at a low false positive rate. As we got considerable accuracy in some models, there is scope for designing an anomaly detection system centered on unsupervised learning. We illustrated how models performed against various malware samples when executed on benign hosts and testbeds. We included a case study to mitigate the adversary attack on the anomaly detection system.

Subject Classification:

Reprints and Corporate Permissions

Please note: Selecting permissions does not provide access to the full text of the article, please see our help page How do I view content?

To request a reprint or corporate permissions for this article, please click on the relevant link below:

Academic Permissions

Please note: Selecting permissions does not provide access to the full text of the article, please see our help page How do I view content?

Obtain permissions instantly via Rightslink by clicking on the button below:

If you are unable to obtain permissions via Rightslink, please complete and submit this Permissions form. For more information, please visit our Permissions help page.