JSM 2013 Home
Online Program Home
My Program

Abstract Details

Activity Number: 318
Type: Contributed
Date/Time: Tuesday, August 6, 2013 : 8:30 AM to 10:20 AM
Sponsor: Section on Statistical Learning and Data Mining
Abstract - #307855
Title: Malware Detection Using Nonparametric Bayesian Clustering and Classification Techniques
Author(s): Yimin Kao*+ and Brian J. Reich and Curtis Storlie
Companies: Department of Statistics, North Carolina State University and North Carolina State University and Los Alamos National Laboratory
Keywords: Classi cation ; Clustering ; Dynamic Trace ; Dirichlet Process Mixture
Abstract:

Computer security requires statistical methods to quickly and accurately flag malicious software. In this talk, we propose a nonparametric Bayesian approach for clustering software and classifying software as benign and malicious. The analysis is based on the dynamic trace of instructions under first-order Markov assumption. Each row of the trace's transition matrix is modeled using the Dirichlet Process Mixture (DPM) model. The DPM clusters software within each class, and produces the Bayes factor which is used for classification. The novelty of the model is using this clustering algorithm to improve the classification accuracy. The simulation study shows that our method outperforms the Elastic Net Logistic (ENL) regression in classification performance under most of the scenarios, and that our model outperforms the Multiple Kernel Learning (MKL) method of clustering results. For the real data analysis, our method gives higher classification accuracy than the ENL method.


Authors who are presenting talks have a * after their name.

Back to the full JSM 2013 program




2013 JSM Online Program Home

For information, contact jsm@amstat.org or phone (888) 231-3473.

If you have questions about the Continuing Education program, please contact the Education Department.

The views expressed here are those of the individual authors and not necessarily those of the JSM sponsors, their officers, or their staff.

ASA Meetings Department  •  732 North Washington Street, Alexandria, VA 22314  •  (703) 684-1221  •  meetings@amstat.org
Copyright © American Statistical Association.