About | Contact Us | Register | Login
ProceedingsSeriesJournalsSearchEAI
Security and Privacy in Communication Networks. 16th EAI International Conference, SecureComm 2020, Washington, DC, USA, October 21-23, 2020, Proceedings, Part II

Research Article

TransNet: Unseen Malware Variants Detection Using Deep Transfer Learning

Download(Requires a free EAI acccount)
2 downloads
Cite
BibTeX Plain Text
  • @INPROCEEDINGS{10.1007/978-3-030-63095-9_5,
        author={Candong Rong and Gaopeng Gou and Mingxin Cui and Gang Xiong and Zhen Li and Li Guo},
        title={TransNet: Unseen Malware Variants Detection Using Deep Transfer Learning},
        proceedings={Security and Privacy in Communication Networks. 16th EAI International Conference, SecureComm 2020, Washington, DC, USA, October 21-23, 2020, Proceedings, Part II},
        proceedings_a={SECURECOMM PART 2},
        year={2020},
        month={12},
        keywords={Deep transfer learning Unseen malware variants detection Network traffic classification.},
        doi={10.1007/978-3-030-63095-9_5}
    }
    
  • Candong Rong
    Gaopeng Gou
    Mingxin Cui
    Gang Xiong
    Zhen Li
    Li Guo
    Year: 2020
    TransNet: Unseen Malware Variants Detection Using Deep Transfer Learning
    SECURECOMM PART 2
    Springer
    DOI: 10.1007/978-3-030-63095-9_5
Candong Rong1, Gaopeng Gou1, Mingxin Cui1, Gang Xiong1, Zhen Li1, Li Guo1,*
  • 1: Institute of Information Engineering
*Contact email: guoli@iie.ac.cn

Abstract

The ever-increasing amount and variety of malware on the Internet have presented significant challenges to the interconnected network community. The emergence of unseen malware variants has resulted in a different distribution of features and labels in the training and testing datasets. For widely used machine learning-based detection methods, the issue of dataset shift will render the trained model ineffective in the face of new data. However, it is a laborious and tedious undertaking whether relearning features to describe new data or collecting large amounts of labeled samples to retrain the classifiers. To address these problems, this paper proposes TransNet, a framework based on deep transfer learning for unseen malware variants detection. We first convert the raw traffic represented by sessions containing data from all layers of the OSI model into fixed-size RGB images through data preprocessing. Afterward, based on the ResNet-50 model pre-trained on the ImageNet, we replace Batch Normalization with Transferable Normalization as the normalization layer to construct our deep transfer learning model. In this way, our approach leverages deep learning to avoid the problem of traditional machine learning in relying on expert knowledge and uses transfer learning to address the issue of domain shift. We test the effectiveness of different methods with a thorough set of experiments. TransNet achieves 95.89% accuracy and 96.09% F-measure on two public datasets from the real-world environment, which is higher than comparative methods. Meantime, our method ranks first on all ten subtasks, showing that it can detect unseen malware variants with stable and excellent performance. Moreover, the distribution discrepancy computed by our method is much smaller than other approaches, which illustrates that our method successfully reduces the shift of data distributions.

Keywords
Deep transfer learning Unseen malware variants detection Network traffic classification.
Published
2020-12-12
Appears in
SpringerLink
http://dx.doi.org/10.1007/978-3-030-63095-9_5
Copyright © 2020–2025 ICST
EBSCOProQuestDBLPDOAJPortico
EAI Logo

About EAI

  • Who We Are
  • Leadership
  • Research Areas
  • Partners
  • Media Center

Community

  • Membership
  • Conference
  • Recognition
  • Sponsor Us

Publish with EAI

  • Publishing
  • Journals
  • Proceedings
  • Books
  • EUDL