Toward an ensemble behavioral-based early evasive malware detection framework

Faitour A. Aboaoja, Anazida Zainal, Fuad A. Ghaleb, Bander Ali Saleh Al-Rimy

Research output: Chapter in Book/Report/Conference proceedingConference contribution

Abstract

Recently malware threats are evolved to be the most cyber security threats. Because of obfuscation and evasion techniques, malware has become more sophisticated in terms of multiple variants representing the same malware function and rapidly evading existing detection approaches. The current solutions extracted the entire data without considering the unrepresentative data that belongs to evasive malware when they recognize that they are executed in controlled environments. In addition, obfuscation techniques such as dead code insertion and reordering instructions aim to produce irrelevant data and make the previous approaches based on names, frequencies, and sequences of the extracted data suffer from low detection rate. To this end, this paper proposes a framework for building an effective early malware detection model that can protect systems and data from evasive malware attacks. Predetermined evasion techniques list is used to extract the most malware behaviors representative data. The Pearson correlation coefficient (r) method is proposed to calculate the correlation between the extracted data to overcome the problem of irrelevant data.

Original languageEnglish
Title of host publication2021 International Conference on Data Science and Its Applications, ICoDSA 2021
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages181-186
Number of pages6
ISBN (Electronic)9781665443036
ISBN (Print)9781665443043
DOIs
Publication statusPublished - 3 Dec 2021
Event2021 International Conference on Data Science and Its Applications, ICoDSA 2021 - Bandung, Indonesia
Duration: 5 Aug 20216 Aug 2021

Conference

Conference2021 International Conference on Data Science and Its Applications, ICoDSA 2021
Country/TerritoryIndonesia
CityBandung
Period5/08/216/08/21

Keywords

  • evasive malware
  • feature extraction
  • malware analysis
  • malware detection and classification
  • obfuscation

Fingerprint

Dive into the research topics of 'Toward an ensemble behavioral-based early evasive malware detection framework'. Together they form a unique fingerprint.

Cite this