Trojan Malware Detection using ANN, Naïve Bayes and SVM Machine Learning Algorithms

Anjelica Castillo, Allen Bryant Lineses, Brenson T. Go, Rogel M. Labanan, Manolito Octaviano · 2022

Trojan malware is one of the most destructive forces in the cyber world that is not easy to detect. In this study, machine learning algorithms namely: Artificial Neural Networks (ANN), Support Vector Machine (SVM), and Naïve Bayes were used to detect computer-based DDoS Trojan malware through network traffic flows. Using the CICDDoS2019 dataset, the Correlation Attribute Evaluation feature in Weka was performed to identify the suitable feature set of the network traffic artifacts for malware detection in a computer system. An ablation feature technique was used in the result to understand the effects of different dataset features on the performance of the models. Moreover, the performance of the models was evaluated using Accuracy, Precision, Recall, F-Metric, Misclassification Rate (FPR), and Receiver Operating Characteristic (ROC). Amongst the machine learning models, the result of the ANN model obtained the highest percentage of correctly classified instances of DDoS Trojan malware. Furthermore, the ANN's model evaluation metrics also showed positive results thus, an indication that the model is suitable for performing DDoS Trojan Malware detection using network traffics. Lastly, the model was also evaluated using Local Interpretable Model - Agnostic Explanations (LiME), and live malware samples were tested.

Read the paper · More papers on PaperTik