Malware Classification of Portable Executables using Tree-Based Ensemble Machine Learning

Venkata Atluri · 2019

The impact of malware and its role in cyber attacks is well known in this current day and age where there is a consistent barrage of cyber attacks on a daily basis. Techniques that can identify the malware that is obfuscated, or has the capabilities to stay hidden, are needed to combat these malware based cyber attacks. In the current study, an attempt is made to study different tree-based ensemble machine learning techniques that can identify malware among windows portable executable (PE) files and the features of importance in the identification of malware. The datasets used in the present research includes both malicious (489 files) and benign (700) portable executable files. The PE file metadata extracted as raw and calculated features (54 features) from the PE file headers. Six different Tree-based ensemble Machine Learning techniques, Bagging Decision Tree Classifier (BDT), Random Forest Classifier (RFC), Extra Trees Classifier (ETC), AdaBoost Classifier (ABC), Gradient Boosting Classifier (GBC), and Voting Ensemble Classifier (VEC) are used to classify the PE files. All the tested classifiers achieved above 95% accuracy and VEC, a voting based ensemble of five tree-based methods performed the best.

Read the paper · More papers on PaperTik