Advancing Business Security in Cloud for Fileless Malware Detection Using Machine Learning
摘要
Advancing Business Security in Cloud for Fileless Malware Detection Using Machine Learning outlines a comprehensive strategy against fileless malware threats. The methodology involves acquiring volatile memory dumps at the hypervisor level securely, followed by rigorous analysis, feature extraction, and model training using Support Vector Machine (SVM), K-Nearest Neighbors (KNN), and Random Forest (RF). SVM consistently demonstrates high precision and recall values across different feature selection scenarios, indicating its ability to accurately identify positive cases while minimizing false positives and false negatives. Moreover, the proposal suggests deploying the model in a cloud environment, enabling the integration of an AI agent-based smart evidence collection and analysis module. This innovative approach ensures the secure acquisition and analysis of evidence for forensic experts, thereby optimizing their response to evolving cyber threats within the realm of business intelligence.