Negative Selection Algorithm with Penalty Factor

Ying Tan · 2016

A malware detection model based on a negative selection algorithm with a penalty factor is proposed to overcome the drawback of traditional negative selection algorithms in defining the harmfulness of self and nonself. The effectiveness of the proposed model is improved greatly by using the dangerous signatures that would have been discarded in the traditional negative selection algorithm. This chapter presents a malware detection model based on a negative selection algorithm with penalty factor (NSAPF). The proposed NSAPF model consists of a malware signature extraction module (MSEM) and a suspicious program detection module (SPDM). In the SPDM, signatures of suspicious programs are extracted using the malware instruction library (MIL). The chapter considers the malware candidate signature library (MCSL) as nonself and the BPMSL as self and generates a Malware Detection Signature Library (MDSL) using NSAPF. Comprehensive experimental results demonstrated that the proposed model is effective in detecting unknown malware with a lower FPRs.

Read the paper · More papers on PaperTik