Research Article

Real-Time Malware Process Detection and Automated Process Killing

Table 6

Average resource consumption over 100 iterations for a batch size of 100 vs. F1-scores on validation and test set for classification and process killing across 14 models..

Modeln featuresAvg. cpu ()Avg. dram (W)Avg. Duration ()Val F1Kill val F1Test F1Kill test F1

AdaBoost26127967.847981.516595.3788.3574.3677.1960.09
AdaBoost37125041.207142.936469.1689.6376.0780.1060.14
DT263905.63202.65128.0297.3988.4866.4462.95
DT372113.67134.29106.6596.3283.5779.6162.50
GBDT268788.41338.78349.3192.2778.2682.4763.33
GBDT3711005.80486.46329.4593.1380.2684.9463.46
MLP2611044.88645.14461.0482.8470.1841.6257.65
MLP3712932.09628.64555.4273.0067.6357.6657.26
NB266947.67297.87185.7375.8067.4262.9056.11
NB375187.96258.80177.3775.5867.6161.8855.33
RF26238621.2011052.848997.3197.1292.9771.5875.97
RF37236598.449967.638879.9796.5791.0585.5577.85
RNN26887664.3148885.9627869.3097.4490.7074.9173.08
RNN37312108.0717120.9010414.5894.6187.3177.6671.95
SVM266630490.84464082.07282026.5778.3467.0468.1656.91
SVM377792179.78730786.06429081.3164.8965.6861.3956.25