Detection of obfuscated malware by engineering memory functions applying ELM
Autor
Moraga, Leonardo Igor
Rivelli Malcó, Juan Pablo
Zabala-Blanco, David
Ahumada-García, Roberto
Azurdia-Meza, Cesar A.
Dehghan Firoozabadi, Ali
Fecha
2023Resumen
Memory analysis is critical to detecting malicious processes, as it can capture various characteristics and behaviors. However, although it is a field in full research, there are still some major obstacles in malware detection, such as optimizing the detection rate and countering advanced malware obfuscation. Since advanced malware uses obfuscation and other techniques to hide from detection methods, there is a great need for an efficient framework that focuses on combating obfuscation and detecting hidden malware. This work proposes an extreme learning machine (ELM) trained with a database of viruses, classified into families of Trojans, spyware, and ransomware. The performance of different ELMs will be implemented and analyzed, among them, the standard ELM, regularized ELM, unbalanced ELM I and II. Its performance will be studied both in binary classification and in multiple classifications, in order to train an antivirus capable of combating the aforementioned difficulties. Prior to obtaining the results, the operating principle of these autonomous learning methods and the methodology to be followed are explained. Finally, the results obtained for each learning method are compared.
Fuente
IEEE Colombian Conference on Applications of Computational Intelligence (ColCACI), 2023, 1-6Link de Acceso
Click aquí para ver el documentoIdentificador DOI
doi.org/10.1109/ColCACI59285.2023.10226058Colecciones
La publicación tiene asociados los siguientes ficheros de licencia: