Memory Forensics-Based Malware Detection Using Computer Vision and Machine Learning

Malware has recently grown exponentially in recent years and poses a serious threat to individual users, corporations, banks, and government agencies. This can be seen from the growth of Advanced Persistent Threats (APTs) that make use of advance and sophisticated malware. With the wide availability...

Full description

Saved in:
Bibliographic Details
Main Authors: Shah S.S.H., Ahmad A.R., Jamil N., Khan A.U.R.
Other Authors: 57878344500
Format: Article
Published: MDPI 2023
Tags: Add Tag
No Tags, Be the first to tag this record!
id my.uniten.dspace-26795
record_format dspace
spelling my.uniten.dspace-267952023-05-29T17:36:46Z Memory Forensics-Based Malware Detection Using Computer Vision and Machine Learning Shah S.S.H. Ahmad A.R. Jamil N. Khan A.U.R. 57878344500 57878026300 36682671900 55602487700 Malware has recently grown exponentially in recent years and poses a serious threat to individual users, corporations, banks, and government agencies. This can be seen from the growth of Advanced Persistent Threats (APTs) that make use of advance and sophisticated malware. With the wide availability of computer-automated tools such as constructors, email flooders, and spoofers. Thus, it is now easy for users who are not technically inclined to create variations in existing malware. Researchers have developed various defense techniques in response to these threats, such as static and dynamic malware analyses. These techniques are ineffective at detecting new malware in the main memory of the computer and otherwise require considerable effort and domain-specific expertise. Moreover, recent techniques of malware detection require a long time for training and occupy a large amount of memory due to their reliance on multiple factors. In this paper, we propose a computer vision-based technique for detecting malware that resides in the main computer memory in which our technique is faster or memory efficient. It works by taking portable executables in a virtual environment to extract memory dump files from the volatile memory and transform them into a particular image format. The computer vision-based contrast-limited adaptive histogram equalization and the wavelet transform are used to improve the contrast of neighboring pixel and to reduce the entropy. We then use the support vector machine, random forest, decision tree, and XGBOOST machine learning classifiers to train the model on the transformed images with dimensions of 112 � 112 and 56 � 56. The proposed technique was able to detect and classify malware with an accuracy rate of 97.01%. Its precision, recall, and F1-score were 97.36%, 95.65%, and 96.36%, respectively. Our finding shows that our technique in preparing dataset with more efficient features to be trained by the Machine Learning classifiers has resulted in significant performance in terms of accuracy, precision, recall, F1-score, speed and memory consumption. The performance has superseded most of the existing techniques in its unique approach. � 2022 by the authors. Final 2023-05-29T09:36:46Z 2023-05-29T09:36:46Z 2022 Article 10.3390/electronics11162579 2-s2.0-85137398687 https://www.scopus.com/inward/record.uri?eid=2-s2.0-85137398687&doi=10.3390%2felectronics11162579&partnerID=40&md5=0d2d1b9ba388641bfb5e5c0fd125a0a2 https://irepository.uniten.edu.my/handle/123456789/26795 11 16 2579 All Open Access, Gold MDPI Scopus
institution Universiti Tenaga Nasional
building UNITEN Library
collection Institutional Repository
continent Asia
country Malaysia
content_provider Universiti Tenaga Nasional
content_source UNITEN Institutional Repository
url_provider http://dspace.uniten.edu.my/
description Malware has recently grown exponentially in recent years and poses a serious threat to individual users, corporations, banks, and government agencies. This can be seen from the growth of Advanced Persistent Threats (APTs) that make use of advance and sophisticated malware. With the wide availability of computer-automated tools such as constructors, email flooders, and spoofers. Thus, it is now easy for users who are not technically inclined to create variations in existing malware. Researchers have developed various defense techniques in response to these threats, such as static and dynamic malware analyses. These techniques are ineffective at detecting new malware in the main memory of the computer and otherwise require considerable effort and domain-specific expertise. Moreover, recent techniques of malware detection require a long time for training and occupy a large amount of memory due to their reliance on multiple factors. In this paper, we propose a computer vision-based technique for detecting malware that resides in the main computer memory in which our technique is faster or memory efficient. It works by taking portable executables in a virtual environment to extract memory dump files from the volatile memory and transform them into a particular image format. The computer vision-based contrast-limited adaptive histogram equalization and the wavelet transform are used to improve the contrast of neighboring pixel and to reduce the entropy. We then use the support vector machine, random forest, decision tree, and XGBOOST machine learning classifiers to train the model on the transformed images with dimensions of 112 � 112 and 56 � 56. The proposed technique was able to detect and classify malware with an accuracy rate of 97.01%. Its precision, recall, and F1-score were 97.36%, 95.65%, and 96.36%, respectively. Our finding shows that our technique in preparing dataset with more efficient features to be trained by the Machine Learning classifiers has resulted in significant performance in terms of accuracy, precision, recall, F1-score, speed and memory consumption. The performance has superseded most of the existing techniques in its unique approach. � 2022 by the authors.
author2 57878344500
author_facet 57878344500
Shah S.S.H.
Ahmad A.R.
Jamil N.
Khan A.U.R.
format Article
author Shah S.S.H.
Ahmad A.R.
Jamil N.
Khan A.U.R.
spellingShingle Shah S.S.H.
Ahmad A.R.
Jamil N.
Khan A.U.R.
Memory Forensics-Based Malware Detection Using Computer Vision and Machine Learning
author_sort Shah S.S.H.
title Memory Forensics-Based Malware Detection Using Computer Vision and Machine Learning
title_short Memory Forensics-Based Malware Detection Using Computer Vision and Machine Learning
title_full Memory Forensics-Based Malware Detection Using Computer Vision and Machine Learning
title_fullStr Memory Forensics-Based Malware Detection Using Computer Vision and Machine Learning
title_full_unstemmed Memory Forensics-Based Malware Detection Using Computer Vision and Machine Learning
title_sort memory forensics-based malware detection using computer vision and machine learning
publisher MDPI
publishDate 2023
_version_ 1806425789209509888
score 13.211869