Deep Learning for Obfuscated Malware Detection Using Memory Dumps
Open Access DepositedObfuscated malware (OM) injects malicious code to operating system memory without leaving traces on files within it. The increasing deleterious capabilities of OM are rapidly changing the cyber threat landscape. Proactive detection of OM is required to protect information technology resources. Incidents involving OM continue to evade detection by traditional antivirus solutions. Signature-based detection methods have a record of ineffectiveness in identifying malicious processes within the memory. Machine Learning (ML) has been used in numerous research works as a mechanism to detect these types of attacks. This paper explores the efficacy and efficiency of Deep Learning (DL) models to detect OM making use of features extracted from memory dumps. Memory dumps provide runtime information that contains behavioral characteristics which are often overlooked during static analysis. A comprehensive dataset containing features from OM samples and benign programs was applied, which have a balanced representation of various malware categories, including ransomware, trojans, and spyware. Each malware category in the dataset was further divided into families with unique characteristics. This praxis used DL to analyze features from memory to detect OM. The objective of this praxis was to determine if there was any significant difference in performance between DL models in OM detection as well as between models using different rescaling techniques.
- All rights reserved
Notice to Authors
If you are the author of this work and you have any questions about the information on this page, please use the Contact form to get in touch with us.