Malware Detection based on Cascading XGBoost and Cost Sensitive
Di Jia Wu, Peiqi Guo, Peng Wei Wang · 2020
Malware which in general are programs that developed for malicious purpose can be used to change or destroy data, run destructive or intrusive programs, and steal personal or other sensitive information. Malware are becoming more and more complex by keeping evolving with technology development. Newly emerged malware has enhanced the ability of survival and anti-detection, and have become a serious safety problem for corporations, government agencies, and individuals. Most previous researches about malware detection using machine learning are based on balanced samples. However, the proportion of benign code and malicious code in real program is extremely unbalanced. In this paper, we propose a malware detection method based on three-tier cascading XGBoost and cost sensitive to improve the ability to deal with unbalanced data. In this model, we extract the API called by PE file to construct the features and use three-tier cascading XGBoost to balance the data and classify. The result of the experiment indicate that this method has high accuracy for malicious code detection of unbalanced samples.