In recent years, the rise in computer threats, especially malware attacks, has led to research on various ways to detect and contain malware attacks. Malware detection approaches can be static, dynamic, or hybrid. Windows portable Executable (WPE) is the file format used by Microsoft windows for an executable file. Previous work based on static features of WPE provides acceptable accuracy, but it can't detect and judge malicious behavior during the execution of malware. This study utilized the EMBER dataset consisting of labeled benign and malicious samples of WPE files. Features based on API import calls are used to predict malicious and benign behavior of WPE files. The random forest, XGBoost, and LightGBM are applied over the collected dataset consisting of 1000 API call features of 1.55 million samples. Chi-Square and Gini importance-based feature selection techniques are used to find the top 200 features, whereas further machine learning models are trained over different feature subsets. Models trained over features selected using hybrid feature selection performed better than Chi-square-based feature selection. All models are analyzed and evaluated using standard performance measures where random forest outperformed with the accuracy of 90 using 150 features.
Skip Nav Destination
,
,
Article navigation
28 April 2023
COMPUTATIONAL INTELLIGENCE AND NETWORK SECURITY
3–4 March 2022
Raipur (C.G), India
Research Article|
April 28 2023
Static malware detection of Ember windows-PE API call using machine learning Available to Purchase
Omkar Shinde;
Omkar Shinde
a)
1
Department of Computer Engineering, College of Engineering Pune, Savitribai Phule Pune University
, Pune, India
a)Corresponding author: [email protected]
Search for other works by this author on:
Anish Khobragade;
Anish Khobragade
b)
1
Department of Computer Engineering, College of Engineering Pune, Savitribai Phule Pune University
, Pune, India
Search for other works by this author on:
Pooja Agrawal
Pooja Agrawal
c)
1
Department of Computer Engineering, College of Engineering Pune, Savitribai Phule Pune University
, Pune, India
Search for other works by this author on:
Omkar Shinde
1,a)
Anish Khobragade
1,b)
Pooja Agrawal
1,c)
1
Department of Computer Engineering, College of Engineering Pune, Savitribai Phule Pune University
, Pune, India
AIP Conf. Proc. 2724, 020001 (2023)
Citation
Omkar Shinde, Anish Khobragade, Pooja Agrawal; Static malware detection of Ember windows-PE API call using machine learning. AIP Conf. Proc. 28 April 2023; 2724 (1): 020001. https://doi.org/10.1063/5.0130256
Download citation file:
Pay-Per-View Access
$40.00
Sign In
You could not be signed in. Please check your credentials and make sure you have an active account and try again.
Citing articles via
The implementation of reflective assessment using Gibbs’ reflective cycle in assessing students’ writing skill
Lala Nurlatifah, Pupung Purnawarman, et al.
Classification data mining with Laplacian Smoothing on Naïve Bayes method
Ananda P. Noto, Dewi R. S. Saputro
Effect of coupling agent type on the self-cleaning and anti-reflective behaviour of advance nanocoating for PV panels application
Taha Tareq Mohammed, Hadia Kadhim Judran, et al.
Related Content
A preliminary study for Malware detection across various platforms
AIP Conf. Proc. (April 2025)
Unified Malware detection approach: Leveraging optimal features across diverse platforms
AIP Conf. Proc. (March 2025)
A comprehensive survey on robust Malware detection model learning from adversarial attacks
AIP Conf. Proc. (December 2024)
Application of machine learning in malware detection for Android
AIP Conf. Proc. (November 2023)
An overview of the latest developments in malware detection using deep learning
AIP Conf. Proc. (April 2025)