Skip to main navigation Skip to search Skip to main content

A Hybrid Anomaly Detection Approach for Obfuscated Malware

  • Gerard Shu Fuhnwi
  • , Matthew Revelle
  • , Clemente Izurieta

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

6 Scopus citations

Abstract

With the rapid evolution of malicious software, cyber threats have become increasingly sophisticated, em-ploying advanced obfuscation techniques to evade traditional detection methods. This study presents a hybrid anomaly detection approach applied to obfuscated malware. Even though there is a large body of research in this field, existing malware detection techniques have drawbacks, such as requiring large amounts of data, trustworthiness (imprecise results) of algorithms, and advanced obfuscation. There is a need to employ solid and efficient techniques for mal-ware detection to overcome these challenges. This paper proposes a hybrid approach, combining an autoencoder with traditional machine-learning methods to create an efficient malware detection framework. We used the malware memory dataset (MalMemAnalysis-2022) to evaluate this framework. The experimental results show our proposed approach can detect obfuscated malware when a deep autoencoder used for feature learning is combined with logistic regression. It is extremely fast with an Accuracy, Detection Rate (DR), Matthew Correlation Coefficient(MCC), and Statistical Parity Difference (SPD) of 99.97%, 99.98%, 99.93%, and 0.03%, respectively.

Original languageEnglish
Title of host publicationProceedings of the 2024 IEEE International Conference on Cyber Security and Resilience, CSR 2024
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages159-165
Number of pages7
ISBN (Electronic)9798350375367
ISBN (Print)9798350375367
DOIs
StatePublished - Sep 24 2024
Event2024 IEEE International Conference on Cyber Security and Resilience, CSR 2024 - Hybrid, London, United Kingdom
Duration: Sep 2 2024Sep 4 2024

Publication series

NameProceedings of the 2024 IEEE International Conference on Cyber Security and Resilience, CSR 2024

Conference

Conference2024 IEEE International Conference on Cyber Security and Resilience, CSR 2024
Country/TerritoryUnited Kingdom
CityHybrid, London
Period09/2/2409/4/24

Keywords

  • Deep Autoencoder
  • Hybrid Anomaly Detection
  • Logistic Regression
  • Malware Detection
  • Obfuscated Malware

INL Publication Number

  • NA

Fingerprint

Dive into the research topics of 'A Hybrid Anomaly Detection Approach for Obfuscated Malware'. Together they form a unique fingerprint.

Cite this