<p>In recent years, the proliferation of malware production tools and the advancement of ChatGPT has led to a significant increase in the number of malware and its variants. Consequently, the detection of malware families has become increasingly important. However, the growing use of sophisticated encryption and obfuscation techniques by malware has further complicated static and dynamic detection methods. Furthermore, the rise of file-less malware, which can evade most static detection methods, has become a prominent trend in infecting victims’ devices. Because malicious software needs to decrypt or de-obfuscate its code and data segments during execution, we can obtain critical information by examining the memory dump of the malware process. Therefore, we propose MIL-CNN, a lightweight neural network based on the attention mechanism for malware classification, utilizing RGB images of malware memory dumps. When compared to other deep learning-based methods, our proposed model not only reduces the number of trainable parameters but also maintains classification accuracy. Experimental results demonstrate that our proposed model achieves a recognition accuracy of 98.1% on the Dumpware10 dataset, surpassing the classification accuracy of existing benchmark models. This highlights the potential of the attention-based lightweight neural network in effectively classifying malware and addressing the challenges posed by encryption, obfuscation, and file-less malware techniques. </p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

A lightweight CNN malware classification method for software detection

  • Jiahui Chen,
  • Mingrui Wu,
  • Wensheng Gan,
  • Huiwu Huang,
  • Terry Shue Chien Lau

摘要

In recent years, the proliferation of malware production tools and the advancement of ChatGPT has led to a significant increase in the number of malware and its variants. Consequently, the detection of malware families has become increasingly important. However, the growing use of sophisticated encryption and obfuscation techniques by malware has further complicated static and dynamic detection methods. Furthermore, the rise of file-less malware, which can evade most static detection methods, has become a prominent trend in infecting victims’ devices. Because malicious software needs to decrypt or de-obfuscate its code and data segments during execution, we can obtain critical information by examining the memory dump of the malware process. Therefore, we propose MIL-CNN, a lightweight neural network based on the attention mechanism for malware classification, utilizing RGB images of malware memory dumps. When compared to other deep learning-based methods, our proposed model not only reduces the number of trainable parameters but also maintains classification accuracy. Experimental results demonstrate that our proposed model achieves a recognition accuracy of 98.1% on the Dumpware10 dataset, surpassing the classification accuracy of existing benchmark models. This highlights the potential of the attention-based lightweight neural network in effectively classifying malware and addressing the challenges posed by encryption, obfuscation, and file-less malware techniques.