Skip to main navigation Skip to search Skip to main content

Malicious powershell detection using graph convolution network

    Research output: Contribution to journalJournal articlepeer-review

    Abstract

    The internet’s rapid growth has resulted in an increase in the number of malicious files. Recently, powershell scripts and Windows portable executable (PE) files have been used in malicious behaviors. To solve these problems, artificial intelligence (AI) based malware detection methods have been widely studied. Among AI techniques, the graph convolution network (GCN) was recently introduced. Here, we propose a malicious powershell detection method using a GCN. To use the GCN, we needed an adjacency matrix. Therefore, we proposed an adjacency matrix generation method using the Jaccard similarity. In addition, we show that the malicious powershell detection rate is increased by approximately 8.2% using GCN.

    Original languageEnglish
    Article number6429
    JournalApplied Sciences (Switzerland)
    Volume11
    Issue number14
    DOIs
    StatePublished - 2021.07.2

    Keywords

    • Adjacency matrix
    • Graph convolution network
    • Powershell

    Quacquarelli Symonds(QS) Subject Topics

    • Materials Science
    • Computer Science & Information Systems
    • Engineering - Petroleum
    • Data Science
    • Engineering - Chemical
    • Physics & Astronomy

    Fingerprint

    Dive into the research topics of 'Malicious powershell detection using graph convolution network'. Together they form a unique fingerprint.

    Cite this