• Complex
  • Title
  • Keyword
  • Abstract
  • Scholars
  • Journal
  • ISSN
  • Conference
搜索

Author:

Wang, Xiao (Wang, Xiao.) | Zhang, Jianbiao (Zhang, Jianbiao.) (Scholars:张建标) | Zhang, Ai (Zhang, Ai.) | Ren, Jinchang (Ren, Jinchang.)

Indexed by:

EI Scopus SCIE PubMed

Abstract:

The promotion of cloud computing makes the virtual machine (VM) increasingly a target of malware attacks in cybersecurity such as those by kernel rootkits. Memory forensic, which observes the malicious tracks from the memory aspect, is a useful way for malware detection. In this paper, we propose a novel TKRD method to automatically detect kernel rootkits in VMs from private cloud, by combining VM memory forensic analysis with bio-inspired machine learning technology. Malicious features are extracted from the memory dumps of the VM through memory forensic analysis method. Based on these features, various machine learning classifiers are trained including Decision tree, Rule based classifiers, Bayesian and Support vector machines (SVM). The experiment results show that the Random Forest classifier has the best performance which can effectively detect unknown kernel rootkits with an Accuracy of 0.986 and an AUC value (the area under the receiver operating characteristic curve) of 0.998.

Keyword:

memory forensic machine learning virtual machine private cloud kernel rootkit detection

Author Community:

  • [ 1 ] [Wang, Xiao]Beijing Univ Technol, Fac Informat Technol, Beijing 100124, Peoples R China
  • [ 2 ] [Zhang, Jianbiao]Beijing Univ Technol, Fac Informat Technol, Beijing 100124, Peoples R China
  • [ 3 ] [Wang, Xiao]Beijing Key Lab Trusted Comp, Beijing 100124, Peoples R China
  • [ 4 ] [Zhang, Jianbiao]Beijing Key Lab Trusted Comp, Beijing 100124, Peoples R China
  • [ 5 ] [Zhang, Ai]Univ Calif San Diego, Dept Comp Sci & Engn, San Diego, CA USA
  • [ 6 ] [Ren, Jinchang]Univ Strathclyde, Dept Elect & Elect Engn, Glasgow, Lanark, Scotland

Reprint Author's Address:

  • 张建标

    [Zhang, Jianbiao]Beijing Univ Technol, Fac Informat Technol, Beijing 100124, Peoples R China;;[Zhang, Jianbiao]Beijing Key Lab Trusted Comp, Beijing 100124, Peoples R China

Show more details

Related Keywords:

Related Article:

Source :

MATHEMATICAL BIOSCIENCES AND ENGINEERING

ISSN: 1547-1063

Year: 2019

Issue: 4

Volume: 16

Page: 2650-2667

2 . 6 0 0

JCR@2022

ESI Discipline: MATHEMATICS;

ESI HC Threshold:54

Cited Count:

WoS CC Cited Count: 16

SCOPUS Cited Count: 32

ESI Highly Cited Papers on the List: 0 Unfold All

WanFang Cited Count:

Chinese Cited Count:

30 Days PV: 7

Online/Total:389/10629534
Address:BJUT Library(100 Pingleyuan,Chaoyang District,Beijing 100124, China Post Code:100124) Contact Us:010-67392185
Copyright:BJUT Library Technical Support:Beijing Aegean Software Co., Ltd.