Show simple item record

dc.contributor.authorCordeiro De Amorim, Renato
dc.contributor.authorKomisarczuk, Peter
dc.contributor.editorIssac, Biju
dc.contributor.editorIsrar, Nauman
dc.date.accessioned2016-04-07T11:41:29Z
dc.date.available2016-04-07T11:41:29Z
dc.date.issued2014-09
dc.identifier.citationCordeiro De Amorim , R & Komisarczuk , P 2014 , Towards effective malware clustering : reducing false negatives through feature weighting and the Lp metric . in B Issac & N Israr (eds) , Case Studies in Secure Computing : Achievements and Trends . CRC Press , pp. 295-310 .
dc.identifier.isbn9781482207064
dc.identifier.otherPURE: 9822830
dc.identifier.otherPURE UUID: fb0ad05c-8630-43e1-8b0d-9b0f4ee019da
dc.identifier.otherScopus: 85054282098
dc.identifier.urihttp://hdl.handle.net/2299/17081
dc.description.abstractIn this paper we present a novel method to reduce the incidence of false negatives in the clustering of malware detected during drive-by-download attacks. Our method comprises the use of a high-interaction client honey-pot called Capture-HPC to acquire behavioural system and network data, and the application of clustering analysis. Our method addresses various issues in clustering, including (i) finding the number of clusters in the dataset, (ii) finding good initial centroids, (iii) determining the relevance of each of the features at each cluster. Our method applies partitional clustering based on the Minkowski Weighted K-Means (Lp) and anomalous pattern initialization. We have performed various experiments on a dataset containing the behaviour of 17,000 possibly infected websites gathered from sources of malicious URLs. We find that our method produces a smaller within cluster variance and a lower quantity of false negatives than other popular clustering algorithms such as K-Means and the Ward's method.en
dc.language.isoeng
dc.publisherCRC Press
dc.relation.ispartofCase Studies in Secure Computing
dc.titleTowards effective malware clustering : reducing false negatives through feature weighting and the Lp metricen
dc.contributor.institutionSchool of Computer Science
dc.description.statusPeer reviewed
rioxxterms.typeOther
herts.preservation.rarelyaccessedtrue


Files in this item

FilesSizeFormatView

There are no files associated with this item.

This item appears in the following Collection(s)

Show simple item record