Immune-based model for malware detection

Jinglin Hu · Jisuanji yingyong yanjiu · 2010

In order to solve the problems existing in the current malware detection especially unknown malware detection, this paper proposed a new malware detection model based on immune. In this model, the IRP request sequences created by running programs regarded as antigen, and the normal programs in operating system were self, malwares were nonself. The nonself would be detected by some antibodies using artificial immunology. Experimental results reveal that this model has high true positive rate, and low false positive and false negative rate. It’s an efficient method for malware detection.

Read the paper · More papers on PaperTik