Memory Visualization-Based Malware Detection Technique

被引:4
|
作者
Shah, Syed Shakir Hameed [1 ]
Jamil, Norziana [1 ]
Khan, Atta Ur Rehman [2 ]
机构
[1] Univ Tenaga Nas, Coll Comp & Informat, Inst Energy Infrastruct, Kajang 43000, Malaysia
[2] Ajman Univ, Coll Engn & IT, Ajman 346, U Arab Emirates
关键词
malware analysis; polymorphic malware; memory analysis; machine learning; denoising filters; wavelet transform; computer vision; advanced persistent threat; energy security; NOISE; FORENSICS;
D O I
10.3390/s22197611
中图分类号
O65 [分析化学];
学科分类号
070302 ; 081704 ;
摘要
Advanced Persistent Threat is an attack campaign in which an intruder or team of intruders establishes a long-term presence on a network to mine sensitive data, which becomes more dangerous when combined with polymorphic malware. This type of malware is not only undetectable, but it also generates multiple variants of the same type of malware in the network and remains in the system's main memory to avoid detection. Few researchers employ a visualization approach based on a computer's memory to detect and classify various classes of malware. However, a preprocessing step of denoising the malware images was not considered, which results in an overfitting problem and prevents us from perfectly generalizing a model. In this paper, we introduce a new data engineering approach comprising two main stages: Denoising and Re-Dimensioning. The first aims at reducing or ideally removing the noise in the malware's memory-based dump files' transformed images. The latter further processes the cleaned image by compressing them to reduce their dimensionality. This is to avoid the overfitting issue and lower the variance, computing cost, and memory utilization. We then built our machine learning model that implements the new data engineering approach and the result shows that the performance metrics of 97.82% for accuracy, 97.66% for precision, 97.25% for recall, and 97.57% for f1-score are obtained. Our new data engineering approach and machine learning model outperform existing solutions by 0.83% accuracy, 0.30% precision, 1.67% recall, and 1.25% f1-score. In addition to that, the computational time and memory usage have also reduced significantly.
引用
收藏
页数:38
相关论文
共 50 条
  • [1] SoK: Visualization-based Malware Detection Techniques
    Brosolo, Matteo
    Vinod, P.
    Asmitha, K. A.
    Rehiman, Rafidha K. A.
    Conti, Mauro
    19TH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY, AND SECURITY, ARES 2024, 2024,
  • [2] Disarming visualization-based approaches in malware detection systems
    Fasci, Lara Saidia
    Fisichella, Marco
    Lax, Gianluca
    Qian, Chenyi
    COMPUTERS & SECURITY, 2023, 126
  • [3] Attacks on Visualization-Based Malware Detection: Balancing Effectiveness and Executability
    Benkraouda, Hadjer
    Qian, Jingyu
    Tran, Hung Quoc
    Kaplan, Berkay
    DEPLOYABLE MACHINE LEARNING FOR SECURITY DEFENSE, MLHAT 2021, 2021, 1482 : 107 - 131
  • [4] Performance comparison of visualization-based malware detection and classification techniques
    Shah, Syed Shakir Hameed
    Jamil, Norziana
    Khan, Atta Ur Rehman
    2022 17TH INTERNATIONAL CONFERENCE ON EMERGING TECHNOLOGIES (ICET'22), 2022, : 200 - 205
  • [5] Disarming visualization-based approaches in malware detection systems (Vol 126, 103062, 2023)
    Fasci, Lara Saidia
    Fisichella, Marco
    Lax, Gianluca
    Qian, Chenyi
    COMPUTERS & SECURITY, 2024, 144
  • [6] PAFE: A lightweight visualization-based fast malware classification method
    Li, Sicong
    Wang, Jian
    Wang, Shuo
    Song, Yafei
    HELIYON, 2024, 10 (16)
  • [7] VMCTE: Visualization-Based Malware Classification Using Transfer and Ensemble Learning
    Chen, Zhiguo
    Cao, Jiabing
    CMC-COMPUTERS MATERIALS & CONTINUA, 2023, 75 (02): : 4445 - 4465
  • [8] Data Visualization and Visualization-Based Fault Detection for Chemical Processes
    Wang, Ray C.
    Baldea, Michael
    Edgar, Thomas F.
    PROCESSES, 2017, 5 (03):
  • [9] A novel method for malware detection on ML-based visualization technique
    Liu, Xinbo
    Lin, Yaping
    Li, He
    Zhang, Jiliang
    COMPUTERS & SECURITY, 2020, 89
  • [10] Image Visualization based Malware Detection
    Kancherla, Kesav
    Mukkamala, Srinivas
    2013 IEEE SYMPOSIUM ON COMPUTATIONAL INTELLIGENCE IN CYBER SECURITY (CICS), 2013, : 40 - 44