Deep Learning for Windows Malware Analysis
摘要
Malwares, such as ransomware, Trojans, spyware, and botnets, are the most common cyber-threats that can cause significant damages for organizations, governments, and individuals. Thus, malware analysis and detection are of prevalent importance for security analysts in both industry and academia. Early signature-based and conventional machine learning-based solutions have shown their limits against the huge proliferation and sophistication of recent malware. To deal with this issue, cybersecurity researchers have shifted to deep learning in order to design more efficient malware detection solutions that can ensure detection of known and unknown malware as well as sophisticated ones. In this paper, we provide a comprehensive review of state-of-the-art deep learning-based malware analysis and detection solutions targeting the Microsoft Windows desktop platform, over the period of 2015–2022. We provide a detailed taxonomy that classifies these solutions according to various criteria including the analysis task, the nature of the extracted features, the used features representation method, and the used deep learning algorithms. Furthermore, we discuss these solutions with respect to the size and the nature of the testing dataset, the performance evaluation metrics for the different tasks, and the achieved results. Finally, we put the light on the current research challenges and recommend some promising future research directions.