Research Article

Real-Time Malware Process Detection and Automated Process Killing

Table 9

Summary of process killing models, validation, and test set score metrics [Table 2 of 3].

ModelValTest
f1tnrtprf1tnrtpr

MLPModel_pro71.4356.3079.8357.5452.5369.38
MLPModel_pro mean process tree72.1857.1480.6757.0653.5367.97
MLPModel_pro process tree min alerts: 172.3254.6282.3557.4149.4171.06
MLPModel_pro process tree min alerts: 272.3254.6282.3557.4149.4171.06
MLPModel_pro process tree min alerts: 372.3254.6282.3557.4149.4171.06
MLPModel_pro process tree min alerts: 472.3254.6282.3557.4149.4171.06
MLPModel_pro rolling mean window: 271.7766.3974.7948.8863.1850.35
MLPModel_pro rolling mean window: 372.6568.9174.7949.2363.7150.57
MLPModel_pro rolling mean window: 472.3473.9571.4346.4067.0545.26
MLPModel_pro sum alerts min: 273.8672.2774.7947.1466.4046.50
MLPModel_pro sum alerts min: 373.6878.9970.5945.2768.1243.36
MLPModel_pro sum alerts min: 473.3082.3568.0744.4869.6341.73
MLPModel_pro_tree71.3831.8297.4864.3621.0792.52
MLPRegression_pro_process38.8953.7835.2954.8348.7367.05
MLPRegression_pro_process mean process tree37.3257.1432.7756.7557.3765.15
NBModel_glo_pro67.259.2496.6455.0710.3689.49
NBModel_glo_pro mean process tree67.259.2496.6455.6212.6989.38
NBModel_glo_pro process tree min alerts: 167.259.2496.6455.0010.1889.43
NBModel_glo_pro process tree min alerts: 267.259.2496.6455.0010.1889.43
NBModel_glo_pro process tree min alerts: 367.259.2496.6455.0010.1889.43
NBModel_glo_pro process tree min alerts: 467.259.2496.6455.0010.1889.43
NBModel_glo_pro rolling mean window: 267.6919.3392.4455.2015.1087.05
NBModel_glo_pro rolling mean window: 367.7326.0589.0855.3217.3286.02
NBModel_glo_pro rolling mean window: 467.7631.0986.5554.2821.0881.68
NBModel_glo_pro sum alerts min: 268.1727.7389.0855.7019.4085.64
NBModel_glo_pro sum alerts min: 367.9931.9386.5554.4222.2781.30
NBModel_glo_pro sum alerts min: 468.0336.9784.0351.3225.3973.44
NBModel_pro67.068.4096.6455.607.0392.63
NBModel_pro mean process tree67.068.4096.6456.179.6192.41
NBModel_pro process tree min alerts: 167.068.4096.6455.566.7892.68
NBModel_pro process tree min alerts: 267.068.4096.6455.566.7892.68
NBModel_pro process tree min alerts: 367.068.4096.6455.566.7892.68
NBModel_pro process tree min alerts: 467.068.4096.6455.566.7892.68
NBModel_pro rolling mean window: 267.6919.3392.4456.0113.4189.81
NBModel_pro rolling mean window: 367.5225.2189.0856.1815.8188.78
NBModel_pro rolling mean window: 467.9931.9386.5554.9419.6183.90
NBModel_pro sum alerts min: 268.6129.4189.0856.5218.1488.13
NBModel_pro sum alerts min: 368.2132.7786.5555.2721.3083.63
NBModel_pro sum alerts min: 467.8137.8283.1952.2524.4275.77
NBModel_pro_tree66.1010.6198.3261.258.6392.69
NBModel_pro_tree mean process tree66.1010.6198.3261.258.6392.69
RFModel_glo_pro89.6883.1994.9676.4367.1992.52
RFModel_glo_pro mean process tree90.4884.0395.8076.3467.6691.92
RFModel_glo_pro process tree min alerts: 190.9184.0396.6469.4550.5692.95
RFModel_glo_pro process tree min alerts: 290.9184.0396.6469.4550.5692.95
RFModel_glo_pro process tree min alerts: 390.9184.0396.6469.4550.5692.95
RFModel_glo_pro process tree min alerts: 490.9184.0396.6469.4550.5692.95
RFModel_glo_pro rolling mean window: 292.7094.9690.7680.7778.8889.38
RFModel_glo_pro rolling mean window: 391.3094.9688.2480.1978.6788.51
RFModel_glo_pro rolling mean window: 490.2795.8085.7179.8682.8683.69
RFModel_glo_pro sum alerts min: 291.3094.9688.2481.5081.5387.97
RFModel_glo_pro sum alerts min: 390.2795.8085.7179.9984.0182.76
RFModel_glo_pro sum alerts min: 488.7995.8083.1976.1185.3775.01
RFModel_pro92.3787.3996.6474.5762.7192.95
RFModel_pro mean process tree92.7488.2496.6474.7964.0492.20
RFModel_pro process tree min alerts: 192.7488.2496.6468.7548.2393.39
RFModel_pro process tree min alerts: 292.7488.2496.6468.7548.2393.39
RFModel_pro process tree min alerts: 392.7488.2496.6468.7548.2393.39
RFModel_pro process tree min alerts: 492.7488.2496.6468.7548.2393.39
RFModel_pro rolling mean window: 293.2294.1292.4478.2873.8389.76
RFModel_pro rolling mean window: 391.3894.1289.0877.4773.2588.78
RFModel_pro rolling mean window: 489.9694.1286.5577.0877.7083.85
RFModel_pro sum alerts min: 291.3894.1289.0877.9874.6588.40
RFModel_pro sum alerts min: 389.9694.1286.5577.0577.5283.96
RFModel_pro sum alerts min: 488.5094.1284.0373.1179.3575.61
RFModel_pro_tree90.3582.5898.3274.2052.4492.74
RFRegression_pro_process91.9487.3995.8074.7766.0590.35
SVMModel_glo_pro65.2315.9789.0857.3424.2486.23
SVMModel_glo_pro mean process tree65.2315.9789.0858.1127.3985.91
SVMModel_glo_pro process tree min alerts: 165.2315.9789.0857.3223.8186.45
SVMModel_glo_pro process tree min alerts: 265.2315.9789.0857.3223.8186.45
SVMModel_glo_pro process tree min alerts: 365.2315.9789.0857.3223.8186.45
SVMModel_glo_pro process tree min alerts: 465.2315.9789.0857.3223.8186.45
SVMModel_glo_pro rolling mean window: 265.1526.0584.0357.9833.5281.84
SVMModel_glo_pro rolling mean window: 364.6531.0980.6758.1435.4680.98
SVMModel_glo_pro rolling mean window: 464.3138.6676.4756.7640.3775.34
SVMModel_glo_pro sum alerts min: 265.0536.1378.9958.3539.0879.13
SVMModel_glo_pro sum alerts min: 364.7542.0275.6357.0543.2474.15
SVMModel_glo_pro sum alerts min: 464.8951.2671.4354.7047.4067.59
SVMModel_pro66.475.8896.6456.9210.3393.71