Skip to main navigation Skip to search Skip to main content

Malware detection based on ontology

  • Harbin Institute of Technology Shenzhen

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Malware in form of Internet worms, computer viruses, and Trojan horses poses a major threat to the security of networked systems. So how to describe the behavior knowledge of malware is an interesting and meaningful work. In recent years, different ontology technologies have been proposed to represent domain knowledge. In the study, we apply ontology techniques into the field of malware detection, and propose the malware detection method based on ontology. This method is based on the behavior of malicious code, and makes a knowledge representation of the malware behaviors from a variety of perspectives. We use the common behaviors of individuals to represent the behaviors of a malware family, and use the ontology reasoning mechanism to detect unknown malware samples. Experiments show that the method has high malicious code detection rate and low false alarm rate.

Original languageEnglish
Title of host publicationProceedings of 2017 International Conference on Machine Learning and Cybernetics, ICMLC 2017
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages21-26
Number of pages6
ISBN (Electronic)9781538604069
DOIs
StatePublished - 14 Nov 2017
Externally publishedYes
Event16th International Conference on Machine Learning and Cybernetics, ICMLC 2017 - Ningbo, China
Duration: 9 Jul 201712 Jul 2017

Publication series

NameProceedings of 2017 International Conference on Machine Learning and Cybernetics, ICMLC 2017
Volume1

Conference

Conference16th International Conference on Machine Learning and Cybernetics, ICMLC 2017
Country/TerritoryChina
CityNingbo
Period9/07/1712/07/17

Keywords

  • Dynamic behavior
  • Malware
  • Ontology
  • Rule

Fingerprint

Dive into the research topics of 'Malware detection based on ontology'. Together they form a unique fingerprint.

Cite this