Research Article

Toward Detecting Malware Based on Process-Aware Behaviors

Table 3

Test results comparison with state-of-the-art.

ApproachArgProAccuracy (%)Precision (%)Recall (%)F1-score (%)Pro-time (ms/s)Detect-time (ms/s)

Decision treeNoNo76.3290.2858.9971.3670.250.34
Zhang et al. [6]YesNo91.7697.6485.5991.22206.6517.05
MalPro [35]YesYes96.7896.8296.7896.80135.462.38
Our methodYesYes97.6397.6497.6397.64141.232.41

1Note that Arg. is abbreviated to argument and Pro. to process feature. As for pro-time and detect-time denotes processing time and response time respectively, and ms/s denotes the time consumed by each sample. The data is bolded to indicate the best-performing result in terms of performance metrics. And “Our method” is bolded to distinguish other methods.