Windows Malware Detection using Machine Learning and TF-IDF Enriched API Calls Information

Namita, Prachi, Prabha Sharma · 2022 Second International Conference on Computer Science, Engineering and Applications (ICCSEA) · 2022

API calls present in Windows operating system are used as an important tool of communication by the application programs. These API calls provide meaningful information about program’s behaviour. Further, this information helps in the identification and categorization of these programs into malware or benign. Therefore, this paper uses the API calls information retrieved from the dynamic analysis of malware and benign samples as important features for malware detection. This information is utilized in three different feature sets: (i) API calls usage, (ii) API calls frequency, and (iii) API calls sequences. Additionally, these three feature sets are combined to form another feature set called Integrated API calls feature set. Thereafter, Term-Frequency and Inverse document frequency (TF-IDF) method is applied for determining the importance of each feature present in these feature sets, and the feature sets are then represented in TF-IDF format. Performance of all the aforementioned feature sets is evaluated using machine learning algorithms such as Decision Tree, Support Vector Machine, Logistic Regression and k-Nearest Neighbour. The experimentation results showed that TF-IDF enriched feature sets obtained better performance than API calls feature sets. The TF-IDF enriched integrated API calls feature set reported maximum 99.91% accuracy for Support Vector Machine and Logistic Regression algorithms.

Read the paper · More papers on PaperTik