首页> 外文会议>IEEE International Conference on Big Data >Automated microsoft office macro malware detection using machine learning
【24h】

Automated microsoft office macro malware detection using machine learning

机译:使用机器学习自动检测Microsoft Office宏恶意软件

获取原文

摘要

Macro malware in Microsoft (MS) Office files has long persisted as a cybersecurity threat. Though it ebbed after its initial rampages around the turn of the century, it has reemerged as threat. Attackers are taking a persuasive approach and using document engineering, aided by improved data mining methods, to make MS Office file malware appear legitimate. Recent attacks have targeted specific corporations with malicious documents containing unusually relevant information. This development undermines the ability of users to distinguish between malicious and legitimate MS Office files and intensifies the need for automating macro malware detection. This study proposes a method of classifying MS Office files containing macros as malicious or benign using the K-Nearest Neighbors machine learning algorithm, feature selection, and TFIDF where p-code opcode n-grams (translated VBA macro code) compose the file features. This study achieves a 96.3% file classification accuracy on a sample set of 40 malicious and 118 benign MS Office files containing macros, and it demonstrates the effectiveness of this approach as a potential defense against macro malware. Finally, it discusses the challenges automated macro malware detection faces and possible solutions.
机译:Microsoft(MS)Office文件中的宏恶意软件长期以来一直作为网络安全威胁而存在。尽管在本世纪初,它在最初的暴行之后退缩了,但它重新崛起为威胁。攻击者正在采取一种有说服力的方法,并使用文档工程技术以及改进的数据挖掘方法来使MS Office文件恶意软件看起来合法。最近的攻击已针对特定公司,其恶意文件包含异常相关的信息。这种发展破坏了用户区分恶意和合法MS Office文件的能力,并增强了自动执行宏恶意软件检测的需求。这项研究提出了一种使用K-最近邻居机器学习算法,特征选择和TFIDF将包含宏的MS Office文件分类为恶意或良性的方法,其中p代码操作码n-gram(经转换的VBA宏代码)构成了文件特征。这项研究对包含宏的40个恶意和118个良性MS Office文件的样本集实现了96.3%的文件分类精度,并且证明了该方法作为潜在的防御宏恶意软件的有效性。最后,它讨论了自动化宏恶意软件检测面临的挑战以及可能的解决方案。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号