Malware detection techniques are critical in the modern cyber-warfare, and memory analysis is a key feature in this process. Most common memory analysis methods and tools are based on traditional static and/or dynamic inspection, which may not be efficient against most malware-obfuscation techniques. Therefore, recent studies have analyzed pattern-based methods, specifically using machine learning. However, performance and complexity issues can be obstacles against the adoption of such technique due the large number of parameters available for training and testing. Therefore, one of the challenges of machine learning for obfuscated malware detection is deploying sensitivity analysis seeking to reduce the numerous memory features. Hence, this research inspects the 58 memory features presented by the MalMemAnalysis-2022 dataset, and strives to extract the ones that establish a trade-off between concise malware classification and performance improvement. The here proposed classifier, namely Reduced Feature Random Forest, can increase accuracy to 99.57% and reduce classification time to 0.88 milliseconds.
Related links
Details
Title
Memory Feature Engineering for Performance-Gain in Obfuscated Malware Detection Using Machine Learning and Sensitivity Analysis
Publication Details
Conference proceedings (IEEE Pacific Rim Conference on Communications, Computers, and Signal Processing), pp.1-6
Resource Type
Conference proceeding
Conference
IEEE Pacific Rim Conference on Communications, Computers and Signal Processing (PACRIM) (Victoria, BC, Canada, 08/21/2024–08/24/2024)
Publisher
IEEE
Number of pages
6
Grant note
Pennsylvania State University Beaver campus (10.13039/100008321)