Artificial Intelligence Hybrid Learning Architecture for Malware Families Classification
Yan-Ju Chen, Wen-Han Kuo, Sung-Yun Tsai, Jiann-Liang Chen, Y.F. Chen, Wei-Zhao Xu · 2019
In recent years, the rise of the Internet of Things has led to a gradual expansion of internet services, but most people ignore the importance of information security. This study investigates the characteristics of the malicious traffic that is generated during the operation of malware, and classifies malware into families without using SSL/TLS decryption. In this work, the features of traffic include the total numbers of packets and bits, sending time, packet size, delivery intervals, and others. All of features that are obtained by extracted of traffic flows are integrated into a complex set and a model that can identify the type of malware is trained by machine learning and deep learning. This work solves the problem of imbalanced data in traffic flows using a traffic analysis mechanism and developing a multi-layer network analysis structure that improves the stability and reliability of the proposed training model, to ensure cyber security.