Malware has emerged as a primary tool cybercriminals use to infiltrate victims’ systems and carry out malicious activities remotely. Despite numerous efforts in the literature to detect malware, malware continues to evade detection mechanisms. Thus, we propose a novel malware detection model that identifies the significant APIs and operation-based significant Registry keys and harnesses them with the wave superposition principle to differentiate between benign and malware binaries effectively. We transform the extracted significant APIs and Registry keys from a binary into waves of varying wavelengths and generate a superpositioned waveform by combining all these waves. We propose a technique to assign a unique wavelength for each significant feature by leveraging the prime numbers, allowing us to capture the relationships between the binaries. Further, we present two approaches to convert the superposition waveforms into numerical values to train and test the Machine Learning (ML) models: Region-Specific Area and Region-Specific Extrema. The experimental analysis shows that square, triangle, and sawtooth waves, when combined with the Region-Specific Area approach and Logistic Regression (LR), outperforms all other combinations, achieving over 99.94% accuracy and a False Positive Rate (FPR) of just 0.1%. Notably, the proposed model outperforms the existing state-of-the-art static and dynamic model in terms of evaluation metrics.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Fusion of Significant Features and Superposition Feature Engineering for Malware Detection

  • Rama Krishna Koppanati,
  • Sateesh K. Peddoju,
  • Arya Deshmukh,
  • Lakshya Joshi

摘要

Malware has emerged as a primary tool cybercriminals use to infiltrate victims’ systems and carry out malicious activities remotely. Despite numerous efforts in the literature to detect malware, malware continues to evade detection mechanisms. Thus, we propose a novel malware detection model that identifies the significant APIs and operation-based significant Registry keys and harnesses them with the wave superposition principle to differentiate between benign and malware binaries effectively. We transform the extracted significant APIs and Registry keys from a binary into waves of varying wavelengths and generate a superpositioned waveform by combining all these waves. We propose a technique to assign a unique wavelength for each significant feature by leveraging the prime numbers, allowing us to capture the relationships between the binaries. Further, we present two approaches to convert the superposition waveforms into numerical values to train and test the Machine Learning (ML) models: Region-Specific Area and Region-Specific Extrema. The experimental analysis shows that square, triangle, and sawtooth waves, when combined with the Region-Specific Area approach and Logistic Regression (LR), outperforms all other combinations, achieving over 99.94% accuracy and a False Positive Rate (FPR) of just 0.1%. Notably, the proposed model outperforms the existing state-of-the-art static and dynamic model in terms of evaluation metrics.