错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Unravelling Obfuscated Malware Through Memory Feature Engineering and Ensemble Learning

  • K. M. Yogesh,
  • S. Arpitha,
  • Thompson Stephan,
  • M. Praksha,
  • V. Raghu

摘要

Memory analysis is an essential step in the process of identifying malicious programs since it can capture a variety of traits and behaviours. Malware detection faces a number of severe challenges, including a low detection rate and increasingly sophisticated methods of obfuscation, despite the fact that extensive research is being conducted in this area. Given the evasion techniques employed by advanced malware, a pressing need arises for a robust framework specialized in detecting concealed and obfuscated malware. To address this challenge, the VolMemLyzer, an advanced memory feature extractor tailored for machine learning systems, has been enhanced. An integrated stacked ensemble machine learning model complements this improved tool to establish an effective malware identification framework. Supporting the evaluation of this system is the MalMemAnalysis2022, a dedicated malware memory dataset with the primary aim of faithfully simulating real-world obfuscated malware scenarios for comprehensive testing and analysis. According to the findings, the proposed solution has an accuracy of 91.25% and an F1 score of 95.45%, indicating that it is able to detect obfuscated and concealed malware utilizing memory feature engineering in an incredibly short amount of time.