TY - GEN
T1 - A Hybrid Anomaly Detection Approach for Obfuscated Malware
AU - Fuhnwi, Gerard Shu
AU - Revelle, Matthew
AU - Izurieta, Clemente
N1 - Publisher Copyright:
© 2024 IEEE.
PY - 2024/9/24
Y1 - 2024/9/24
N2 - With the rapid evolution of malicious software, cyber threats have become increasingly sophisticated, em-ploying advanced obfuscation techniques to evade traditional detection methods. This study presents a hybrid anomaly detection approach applied to obfuscated malware. Even though there is a large body of research in this field, existing malware detection techniques have drawbacks, such as requiring large amounts of data, trustworthiness (imprecise results) of algorithms, and advanced obfuscation. There is a need to employ solid and efficient techniques for mal-ware detection to overcome these challenges. This paper proposes a hybrid approach, combining an autoencoder with traditional machine-learning methods to create an efficient malware detection framework. We used the malware memory dataset (MalMemAnalysis-2022) to evaluate this framework. The experimental results show our proposed approach can detect obfuscated malware when a deep autoencoder used for feature learning is combined with logistic regression. It is extremely fast with an Accuracy, Detection Rate (DR), Matthew Correlation Coefficient(MCC), and Statistical Parity Difference (SPD) of 99.97%, 99.98%, 99.93%, and 0.03%, respectively.
AB - With the rapid evolution of malicious software, cyber threats have become increasingly sophisticated, em-ploying advanced obfuscation techniques to evade traditional detection methods. This study presents a hybrid anomaly detection approach applied to obfuscated malware. Even though there is a large body of research in this field, existing malware detection techniques have drawbacks, such as requiring large amounts of data, trustworthiness (imprecise results) of algorithms, and advanced obfuscation. There is a need to employ solid and efficient techniques for mal-ware detection to overcome these challenges. This paper proposes a hybrid approach, combining an autoencoder with traditional machine-learning methods to create an efficient malware detection framework. We used the malware memory dataset (MalMemAnalysis-2022) to evaluate this framework. The experimental results show our proposed approach can detect obfuscated malware when a deep autoencoder used for feature learning is combined with logistic regression. It is extremely fast with an Accuracy, Detection Rate (DR), Matthew Correlation Coefficient(MCC), and Statistical Parity Difference (SPD) of 99.97%, 99.98%, 99.93%, and 0.03%, respectively.
KW - Deep Autoencoder
KW - Hybrid Anomaly Detection
KW - Logistic Regression
KW - Malware Detection
KW - Obfuscated Malware
UR - https://www.scopus.com/pages/publications/85206204023
UR - https://www.mendeley.com/catalogue/7c517131-34b8-3de5-ba4a-49639f44e25f/
U2 - 10.1109/CSR61664.2024.10679474
DO - 10.1109/CSR61664.2024.10679474
M3 - Conference contribution
AN - SCOPUS:85206204023
SN - 9798350375367
T3 - Proceedings of the 2024 IEEE International Conference on Cyber Security and Resilience, CSR 2024
SP - 159
EP - 165
BT - Proceedings of the 2024 IEEE International Conference on Cyber Security and Resilience, CSR 2024
PB - Institute of Electrical and Electronics Engineers Inc.
T2 - 2024 IEEE International Conference on Cyber Security and Resilience, CSR 2024
Y2 - 2 September 2024 through 4 September 2024
ER -