Research Article

Real-Time Malware Process Detection and Automated Process Killing

Table 2

26 process-level features: 22 features + 4 port status values.

Category

CPU use (%)System levelUser level
Memory use (bytes)TotalPhysical (nonswapped)Swap
Child processesCountMaximum process IDNumber of threads
I/O operation bytes on disk (bytes)ReadWriteNonread-write I/O operations
I/O operation count on diskReadWriteNonread-write I/O operations
PriorityProcess priorityI/O process priority
Network # packetsTCP packet countUDP packet count
Network # bytes# Bytes sent# Bytes received
Network otherNumber of connections currently openStatuses of the ports opened by the process (4 statuses)
MiscellaneousNumber of command line arguments passed to processNumber of handles being used by process