Research Article

Real-Time Malware Process Detection and Automated Process Killing

Table 12

Random Forest and Decision Tree each with a minimum requirement of two alerts (“malicious classifications”) to kill a process. F1, TNR, and TPR reported on validation and test set.

Modeln featuresValTest
F1TnrtprF1tnrtpr

RF (alerts: 2)3791.3094.9688.2481.5081.5387.97
DT (rolling mean: 2)2693.1694.9691.6073.8266.1988.40