The Genetic Analysis Malware Pipeline (GAMP)
Open Access DepositedEnhancing Malware Detection via Proactive Multiclass and Binary Classification of Windows Executables
Downloadable Content
The rapid evolution of malware, driven by code obfuscation, polymorphism, and anti-analysis techniques, has made signature-based detection increasingly ineffective. To address this security gap, this praxis proposes a bioinformatics-inspired model for classifying Windows Portable Executable (PE) malware
the Genetic Analysis Malware Pipeline (GAMP). The GAMP uses a three-stage process. PE files are converted into symbolic sequences and compared using sequence alignment to assess similarity. Files are then classified as malware or benign, and malware samples are further attributed to specific families. Benchmarking against the Microsoft BIG 2015 database and the Super Threaded Reference-Free Alignment-Free N-Sequence Decoder (STRAND) model, GAMP achieved an accuracy rate of 99.22%, compared with the STRAND 64-bit version’s accuracy of 97.41% and the STRAND 32-bit version’s accuracy of 91.97%. Independent testing with the Blue Hexagon Open Dataset for Malware Analysis (BODMAS) dataset again demonstrated that GAMP achieved a consistent accuracy rate greater than 95% for both malware family attribution and classification and less than a 3% false positive rate.
- All rights reserved
Notice to Authors
If you are the author of this work and you have any questions about the information on this page, please use the Contact form to get in touch with us.