Other authors

Universitat Politècnica de Catalunya. Departament d'Arquitectura de Computadors

Universitat Politècnica de Catalunya. IMP - Information Modeling and Processing

Publication date

2024



Abstract

The rise in cyber-attacks and cyber-crime is causing more and more organizations and individuals to consider the correct implementation of their security systems. The consequences of a security breach can be devastating, ranging from loss of public confidence to bankruptcy. Traditional techniques for detecting and stopping malware rely on building a database of known signatures using known samples of malware. However, these techniques are not very effective at detecting zero-day exploits because there are no samples in their malware signature databases. To address this challenge, our work proposes a novel approach to malware detection using machine learning techniques. Our solution provides a two-fold contribution, on the one hand, our training the model does not require any kind of malware, as it creates a user profile using only normal user behavior data, detecting malware by identifying deviations from this profile. On the other hand, as we shall see, our solution is able to dynamically train the model using only six sessions to minimize false positives. As a consequence, our model can quickly and effectively detect zero-day malware and other unknown threats without previous knowledge. The proposed approach is evaluated using real-world datasets, and different machine learning algorithms are compared to evaluate their performance in detecting unknown threats. The results show that the proposed approach is effective in detecting malware, achieving high accuracy and low false positive rates.


This work was partially funded by IRIS Artificial Intelligence Threat Reporting and Incident Response System (H2020-101021727).


Peer Reviewed


Postprint (author's final draft)

Document Type

Part of book or chapter of book

Language

English

Publisher

Springer Science and Business Media LLC

Related items

https://link.springer.com/book/10.1007/978-3-031-54129-2

info:eu-repo/grantAgreement/EC/H2020/101021727/EU/artificial Intelligence threat Reporting and Incident response System/IRIS

Recommended citation

This citation was generated automatically.

Rights

Open Access

This item appears in the following Collection(s)

E-prints [72896]