Zero-Day Malware Classification Using Deep Features with Support Vector Machines
Rania A. Elsayed, Amir El-Ghamry, Tarek A-Z K Gaber, Aboul Ella Hassanien · 2021
IoT devices are increasingly used every day. However, their limited resources cause them to be vulnerable to any malware, malicious software that causes harm to any device without the user’s knowledge. Malwares are called zero-day attacks, a serious threat to internet security since they exploit zero-day vulnerabilities with unknown nature, making them difficult to detect. To solve this problem, the structure of these malware need to be known and analyzed, therefore a small dataset of different types of malware including zero-day attack, is live-captured from network traffic to form 1000 PCAP files representing malware and normal behavior that is used as a source for traffic analysis and malware classification. Most traditional malware detection systems proposed in the literature use signature-based methods, so these systems cannot detect unknown malware types. This paper aims to introduce novel IoT image-based malware traffic analysis approaches (i.e., anomaly detection) using machine and deep learning techniques that can detect unknown malware. To achieve better analysis, PCAP files are represented as RGB images, then the supervised machine or deep learning algorithm is carefully selected to achieve the best results. In this paper, seven supervised learning algorithms with different s and levels of complexity are tested and compared with analysis to have the best one selected. The seven s are divided into two categories: Two-Layer CNN, Four-Layer CNN, VGG16, and under the category of CNN classifiers and Logistic Regression, Support Vector Machine, and K-Nearest Neighbours under the category of Ordinary Classifiers. Experimental results show that the highest performance reached is 94% with the SVM classifier on MobileNetv2 features due to its fast and stable training with fewer resources compared to the other models.