Memory Visualization-Based Malware Detection Technique

被引:4
|
作者
Shah, Syed Shakir Hameed [1 ]
Jamil, Norziana [1 ]
Khan, Atta Ur Rehman [2 ]
机构
[1] Univ Tenaga Nas, Coll Comp & Informat, Inst Energy Infrastruct, Kajang 43000, Malaysia
[2] Ajman Univ, Coll Engn & IT, Ajman 346, U Arab Emirates
关键词
malware analysis; polymorphic malware; memory analysis; machine learning; denoising filters; wavelet transform; computer vision; advanced persistent threat; energy security; NOISE; FORENSICS;
D O I
10.3390/s22197611
中图分类号
O65 [分析化学];
学科分类号
070302 ; 081704 ;
摘要
Advanced Persistent Threat is an attack campaign in which an intruder or team of intruders establishes a long-term presence on a network to mine sensitive data, which becomes more dangerous when combined with polymorphic malware. This type of malware is not only undetectable, but it also generates multiple variants of the same type of malware in the network and remains in the system's main memory to avoid detection. Few researchers employ a visualization approach based on a computer's memory to detect and classify various classes of malware. However, a preprocessing step of denoising the malware images was not considered, which results in an overfitting problem and prevents us from perfectly generalizing a model. In this paper, we introduce a new data engineering approach comprising two main stages: Denoising and Re-Dimensioning. The first aims at reducing or ideally removing the noise in the malware's memory-based dump files' transformed images. The latter further processes the cleaned image by compressing them to reduce their dimensionality. This is to avoid the overfitting issue and lower the variance, computing cost, and memory utilization. We then built our machine learning model that implements the new data engineering approach and the result shows that the performance metrics of 97.82% for accuracy, 97.66% for precision, 97.25% for recall, and 97.57% for f1-score are obtained. Our new data engineering approach and machine learning model outperform existing solutions by 0.83% accuracy, 0.30% precision, 1.67% recall, and 1.25% f1-score. In addition to that, the computational time and memory usage have also reduced significantly.
引用
收藏
页数:38
相关论文
共 50 条
  • [21] A visualization-based investigation of dialysis properties
    Xu, L
    Sun, YF
    Li, M
    Yang, JM
    Gao, D
    FRONTIERS ON SEPARATION SCIENCE AND TECHNOLOGY, 2004, : 599 - 604
  • [22] VMW - A VISUALIZATION-BASED MICROARCHITECTURE WORKBENCH
    DIEP, TA
    SHEN, JP
    COMPUTER, 1995, 28 (12) : 57 - +
  • [23] Hybrid visualization-based framework for depressive state detection and characterization of atypical patients
    Kopitar, Leon
    Kokol, Peter
    Stiglic, Gregor
    JOURNAL OF BIOMEDICAL INFORMATICS, 2023, 147
  • [24] DAE: a visualization-based system for data analysis
    Buono, Paolo
    Ardito, Carmelo
    Costabile, Maria Francesca
    Lanzilotti, Rosa
    Piccinno, Antonio
    IEEE SYMPOSIUM ON VISUAL LANGUAGES AND HUMAN-CENTRIC COMPUTING, PROCEEDINGS, 2006, : 147 - +
  • [25] Malware detection based on visualization of recombined API instruction sequence
    Yang, Hongyu
    Zhang, Yupei
    Zhang, Liang
    Cheng, Xiang
    CONNECTION SCIENCE, 2022, 34 (01) : 2630 - 2651
  • [26] Interactive visualization-based surveillance video synopsis
    K. Namitha
    Athi Narayanan
    M. Geetha
    Applied Intelligence, 2022, 52 : 3954 - 3975
  • [27] A Visualization-Based Exploratory Technique for Classifier Comparison with Respect to Multiple Metrics and Multiple Domains
    Alaiz-Rodriguez, Rocio
    Japkowicz, Nathalie
    Tischer, Peter
    MACHINE LEARNING AND KNOWLEDGE DISCOVERY IN DATABASES, PART II, PROCEEDINGS, 2008, 5212 : 660 - +
  • [28] Visualization-Based Active Learning for Video Annotation
    Liao, Hongsen
    Chen, Li
    Song, Yibo
    Ming, Hao
    IEEE TRANSACTIONS ON MULTIMEDIA, 2016, 18 (11) : 2196 - 2205
  • [29] Interactivity Factors in Visualization-Based Exploratory Search
    Baigelenov, Ali
    Parsons, Paul
    CHI 2018: EXTENDED ABSTRACTS OF THE 2018 CHI CONFERENCE ON HUMAN FACTORS IN COMPUTING SYSTEMS, 2018,
  • [30] A visualization-based approach for project portfolio selection
    da Silva, Celmar Guimaraes
    Meidanis, Joao
    Moura, Arnaldo Vieira
    Souza, Maria Angelica
    Viadanna, Paulo, Jr.
    Costa Lima, Gabriel A.
    de Barros, Rafael S. V.
    NEW ADVANCES IN INFORMATION SYSTEMS AND TECHNOLOGIES, VOL 1, 2016, 444 : 835 - 844