Data Mining for Detecting Malicious Executables
Mehedy Masud, Latifur Khan, Bhavani Thuraisingham · Auerbach Publications eBooks · 2011
In this part, we discussed our proposed data mining technique to detect email worms. Di¡erent features, such as total number of words in message body/subject, presence/absence of binary attachments, types of attachments, and others, are extracted from the emails. en the number of features is reduced using a Two-phase Selection (TPS) technique, which is a novel combination of decision tree and greedy selection algorithm. We have used di¡erent classication techniques, such as Support Vector Machine (SVM), Naïve Bayes, and their combination. Finally, the trained classiers are tested on a dataset containing both known and unknown types of worms. Compared to the baseline approaches, our proposed TPS selection along with SVM classication achieves the best accuracy in detecting both known and unknown types of worms.