Memory Forensics-Based Malware Detection Using Computer Vision and Machine Learning
Malware has recently grown exponentially in recent years and poses a serious threat to individual users, corporations, banks, and government agencies. This can be seen from the growth of Advanced Persistent Threats (APTs) that make use of advance and sophisticated malware. With the wide availability...
Saved in:
Main Authors: | , , , |
---|---|
Other Authors: | |
Format: | Article |
Published: |
MDPI
2023
|
Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
Institution: | Universiti Tenaga Nasional |
id |
my.uniten.dspace-26795 |
---|---|
record_format |
dspace |
spelling |
my.uniten.dspace-267952023-05-29T17:36:46Z Memory Forensics-Based Malware Detection Using Computer Vision and Machine Learning Shah S.S.H. Ahmad A.R. Jamil N. Khan A.U.R. 57878344500 57878026300 36682671900 55602487700 Malware has recently grown exponentially in recent years and poses a serious threat to individual users, corporations, banks, and government agencies. This can be seen from the growth of Advanced Persistent Threats (APTs) that make use of advance and sophisticated malware. With the wide availability of computer-automated tools such as constructors, email flooders, and spoofers. Thus, it is now easy for users who are not technically inclined to create variations in existing malware. Researchers have developed various defense techniques in response to these threats, such as static and dynamic malware analyses. These techniques are ineffective at detecting new malware in the main memory of the computer and otherwise require considerable effort and domain-specific expertise. Moreover, recent techniques of malware detection require a long time for training and occupy a large amount of memory due to their reliance on multiple factors. In this paper, we propose a computer vision-based technique for detecting malware that resides in the main computer memory in which our technique is faster or memory efficient. It works by taking portable executables in a virtual environment to extract memory dump files from the volatile memory and transform them into a particular image format. The computer vision-based contrast-limited adaptive histogram equalization and the wavelet transform are used to improve the contrast of neighboring pixel and to reduce the entropy. We then use the support vector machine, random forest, decision tree, and XGBOOST machine learning classifiers to train the model on the transformed images with dimensions of 112 � 112 and 56 � 56. The proposed technique was able to detect and classify malware with an accuracy rate of 97.01%. Its precision, recall, and F1-score were 97.36%, 95.65%, and 96.36%, respectively. Our finding shows that our technique in preparing dataset with more efficient features to be trained by the Machine Learning classifiers has resulted in significant performance in terms of accuracy, precision, recall, F1-score, speed and memory consumption. The performance has superseded most of the existing techniques in its unique approach. � 2022 by the authors. Final 2023-05-29T09:36:46Z 2023-05-29T09:36:46Z 2022 Article 10.3390/electronics11162579 2-s2.0-85137398687 https://www.scopus.com/inward/record.uri?eid=2-s2.0-85137398687&doi=10.3390%2felectronics11162579&partnerID=40&md5=0d2d1b9ba388641bfb5e5c0fd125a0a2 https://irepository.uniten.edu.my/handle/123456789/26795 11 16 2579 All Open Access, Gold MDPI Scopus |
institution |
Universiti Tenaga Nasional |
building |
UNITEN Library |
collection |
Institutional Repository |
continent |
Asia |
country |
Malaysia |
content_provider |
Universiti Tenaga Nasional |
content_source |
UNITEN Institutional Repository |
url_provider |
http://dspace.uniten.edu.my/ |
description |
Malware has recently grown exponentially in recent years and poses a serious threat to individual users, corporations, banks, and government agencies. This can be seen from the growth of Advanced Persistent Threats (APTs) that make use of advance and sophisticated malware. With the wide availability of computer-automated tools such as constructors, email flooders, and spoofers. Thus, it is now easy for users who are not technically inclined to create variations in existing malware. Researchers have developed various defense techniques in response to these threats, such as static and dynamic malware analyses. These techniques are ineffective at detecting new malware in the main memory of the computer and otherwise require considerable effort and domain-specific expertise. Moreover, recent techniques of malware detection require a long time for training and occupy a large amount of memory due to their reliance on multiple factors. In this paper, we propose a computer vision-based technique for detecting malware that resides in the main computer memory in which our technique is faster or memory efficient. It works by taking portable executables in a virtual environment to extract memory dump files from the volatile memory and transform them into a particular image format. The computer vision-based contrast-limited adaptive histogram equalization and the wavelet transform are used to improve the contrast of neighboring pixel and to reduce the entropy. We then use the support vector machine, random forest, decision tree, and XGBOOST machine learning classifiers to train the model on the transformed images with dimensions of 112 � 112 and 56 � 56. The proposed technique was able to detect and classify malware with an accuracy rate of 97.01%. Its precision, recall, and F1-score were 97.36%, 95.65%, and 96.36%, respectively. Our finding shows that our technique in preparing dataset with more efficient features to be trained by the Machine Learning classifiers has resulted in significant performance in terms of accuracy, precision, recall, F1-score, speed and memory consumption. The performance has superseded most of the existing techniques in its unique approach. � 2022 by the authors. |
author2 |
57878344500 |
author_facet |
57878344500 Shah S.S.H. Ahmad A.R. Jamil N. Khan A.U.R. |
format |
Article |
author |
Shah S.S.H. Ahmad A.R. Jamil N. Khan A.U.R. |
spellingShingle |
Shah S.S.H. Ahmad A.R. Jamil N. Khan A.U.R. Memory Forensics-Based Malware Detection Using Computer Vision and Machine Learning |
author_sort |
Shah S.S.H. |
title |
Memory Forensics-Based Malware Detection Using Computer Vision and Machine Learning |
title_short |
Memory Forensics-Based Malware Detection Using Computer Vision and Machine Learning |
title_full |
Memory Forensics-Based Malware Detection Using Computer Vision and Machine Learning |
title_fullStr |
Memory Forensics-Based Malware Detection Using Computer Vision and Machine Learning |
title_full_unstemmed |
Memory Forensics-Based Malware Detection Using Computer Vision and Machine Learning |
title_sort |
memory forensics-based malware detection using computer vision and machine learning |
publisher |
MDPI |
publishDate |
2023 |
_version_ |
1806425789209509888 |