基于WIG-GA特征选择算法的恶意代码检测方法
Malicious Code Detection Method Based on WIG-GA Feature Selection Algorithm
DOI: 10.12677/CSA.2018.83031, PDF,  被引量   
作者: 王 冠*, 郝冉冉:北京工业大学计算机学院,北京;可信计算北京市重点实验室,北京;高尚伟:北京工业大学计算机学院,北京
关键词: 恶意代码特征降维遗传算法分类Malicious Code Dimensionality Reduction Genetic Algorithm Classification
摘要: 针对当前恶意代码检测中特征高维度问题,本文提出一种基于引入频率权重因子的信息增益算法和遗传算法相结合的恶意代码特征选择方法,该方法可以选择出能够有效区分正常代码与恶意代码的最优特征子集,实现特征的降维。该方法利用遗传算法较强的全局搜索能力进行特征子集的搜索,同时采用基于频率权重因子的信息增益算法作为特征子集的适应度评价,最后在当前流行的多种分类方法中进行学习和验证。通过实验表明:该方法可以有效的降低恶意代码检测中特征的维度,有效的提高了分类器的学习效率和精度。
Abstract: In order to solve the problem of feature dimensionality in current malicious code detection, this paper proposes a method of feature selection of malicious code based on information gain algorithm which introduces frequency weight factor and genetic algorithm. This method can select the optimal feature subset that can effectively distinguish between normal code and malicious code, and achieve dimensionality reduction. This method uses the strong global search ability of genetic algo-rithm to search the feature subset. At the same time, the information gain algorithm based on the frequency weighting factor is used as the fitness evaluation of the feature subset. At last, we use a variety of popular classifiers to learn and verify. Experiments show that this method can effectively reduce the dimensions of features in malicious code detection and effectively improve the learning efficiency and accuracy of the classifier.
文章引用:王冠, 郝冉冉, 高尚伟. 基于WIG-GA特征选择算法的恶意代码检测方法[J]. 计算机科学与应用, 2018, 8(3): 266-274. https://doi.org/10.12677/CSA.2018.83031

参考文献

[1] Lee, T., Kim, D., Jeong, H., et al. (2014) Risk Prediction of Malicious Code-Infected Websites by Mining Vulnerability Features. In-ternational Journal of Security & Its Applications, 8, 291-294. [Google Scholar] [CrossRef
[2] Abouassaleh, T., Cercone, N., Kešelj, V., et al. (2004) N-Gram-Based Detection of New Malicious Code. Proceedings of the 28th Annual International Computer Software and Applications Conference, 2, 41-42.
[3] Berrar, D. and Dubitzky, W. (2013) Information Gain. Springer, New York, 1022-1023. [Google Scholar] [CrossRef
[4] 郭宁, 孙晓妍, 林和, 等. 基于属性序约简的恶意代码检测[J]. 计算机应用, 2011, 31(4): 1006-1009.
[5] 张福勇, 赵铁柱. 基于肯定选择分类算法的恶意代码检测方法[J]. 沈阳工业大学学报, 2016, 38(2): 206-210.
[6] 朱红萍, 巩青歌, 雷战波. 基于遗传算法的入侵检测特征选择[J]. 计算机应用研究, 2012, 29(4): 1417-1419.
[7] Reddy, D.K.S., Dash, S.K. and Pujari, A.K. (2006) New Malicious Code Detection Using Variable Length n-Grams. Information Systems Security, 4332, 307-323.
[8] 李盟, 贾晓启, 王蕊, 等. 一种恶意代码特征选取和建模方法[J]. 计算机应用与软件, 2015(8): 266-271.
[9] 陈果, 邓堰. 遗传算法特征选取中的几种适应度函数构造新方法及其应用[J]. 机械科学与技术, 2011, 30(1): 124-128.