Malware Detection via Machine Learning and Recognition of Non Stationary Tasks

Yasamin Hamza Alagrash, Haissam Badih, Julian L. Rrushi · 2020

Most research studies indicate that users are frequently targeted by malware. Mimicry attacks enable malware to operate in ways that are similar to the work of legitimate users. Furthermore, when malware land on a target machine, they carry out operations to explore the compromised machine, as well as to unearth resources that are of benefit to threat actors. In this paper, we describe a machine learning approach that we developed to distinguish non stationary user tasks by analyzing their resource utilization. In the process, our approach predicts the progressive steps in a user task. Our approach collects live performance counter data, which it then prepares and analyzes to recognize and define patterns of resource utilization for a non stationary task.

Read the paper · More papers on PaperTik