Training a multi-criteria decision system and application to the detection of PHP webshells

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

In this paper we present an algorithm designed to train a multi-criteria decision system. This kind of system is very important and used a lot in different military fields and, particularly in cyber-defense. We developed this algorithm to be used with different multi-agent detection systems. The MASFAD system is a typical example [1]. It is a multi-agent system for Advanced Persistent Threat (APT) detection. In this paper we compare different optimization methods for learning Weighted Ordered Weighted Averaging (WOWA) coefficients in order to perform a binary classification. The WOWA function is an aggregation function that is a generalization of OrderedWeighted Averaging (OWA) and the Weighted mean. The WOWA operator combines both of their advantages The learning part is based on a Genetic Algorithm and uses a training dataset. We perform a complete parameter study and we determine the efficiency of our model by evaluating the performance during the classification of different PHP files as webshells or normal files. These PHP files were previously analyzed by a program developed at the Royal Military Academy. We obtain very accurate results and a good stability during the decision process. This system could be used in a lot of different fields.

Original languageEnglish
Title of host publication2019 International Conference on Military Communications and Information Systems, ICMCIS 2019
PublisherInstitute of Electrical and Electronics Engineers Inc.
ISBN (Electronic)9781538693834
DOIs
Publication statusPublished - May 2019
Event2019 International Conference on Military Communications and Information Systems, ICMCIS 2019 - Budva, Montenegro
Duration: 14 May 201915 May 2019

Publication series

Name2019 International Conference on Military Communications and Information Systems, ICMCIS 2019

Conference

Conference2019 International Conference on Military Communications and Information Systems, ICMCIS 2019
Country/TerritoryMontenegro
CityBudva
Period14/05/1915/05/19

Keywords

  • Webshell
  • aggregation functions
  • machine learning
  • multi-criteria decision

Fingerprint

Dive into the research topics of 'Training a multi-criteria decision system and application to the detection of PHP webshells'. Together they form a unique fingerprint.

Cite this