Reputation Based Malware Detection Using Support Vector Machine

2019 
The idea behind this paper is to make faster predictions with low false positive rate in malware detection. We intend to create a trust level between computers on the network using a system of reputation score. Reputation score is employed to indicate health score of specific machine on the network. A machine with low reputation score indicates malicious machine and a machine with high reputation score indicates healthy machine. The files having source of a low reputation machine are discarded whereas files of machine with high reputation score are further processed by an open source sandbox and Support Vector Machine is employed on its behavioral log to identify the threat. If file is malicious then the source machine reputation score is decreased otherwise it is increased. The data is stored in a database as a machine address, reputation score mapping.
    • Correction
    • Source
    • Cite
    • Save
    • Machine Reading By IdeaReader
    5
    References
    0
    Citations
    NaN
    KQI
    []