arrow
Return

Transformer-based malware detection using process resource utilization metrics

delete2025-03-01
delete0
delete
OA
AI
D
Dimosthenis Natsos *
A
Andreas L. Symeonidis
DOI:10.1016/j.rineng.2025.104250delete
deleteOriginal
deleteShare
deleteSave
View PDF
Abstract

Abstract

En 中文
Malware detection has long relied on signature-based methods limited in detecting zero-day malware attacks. Although efficient, these approaches are vulnerable to obfuscation and evasion techniques. To this end, dynamic approaches utilizing process resource-utilization metrics have emerged as promising alternatives. They solve the aforementioned issues, but require large datasets for training and struggle with false-positives and false-negatives. This study is the first to explore the application of Transformers for malware detection using process resource- utilization metrics, encoding input data as sequences of processes, with each process represented by its resource- utilization metrics (e.g., CPU, memory, and disk usage). We compare the proposed Transformer-based architecture with the leading LSTM model in terms of accuracy, precision, recall, F1-score and training time, focusing on performance across varying sample sizes and validate our results with rigorous statistical methodologies. Our findings demonstrate Transformers' ability to maintain high performance even with smaller datasets, thus excel in real-world scenarios of limited data availability, and scale effectively with larger datasets, offering lower false-positive and false-negative rates. We shed light on the models' decision-making processes, introducing the concept of dynamic malware signatures derived from resource-utilization metrics and identifying key features that prominently reflect malware activity. Additionally, we showcase that other tenant processes within the operating system act as indirect indicators of malware presence, providing valuable signals for detection even when the malware process itself is not directly observed. This work establishes Transformers as the state-of-the-art solution for malware detection using process resource-utilization metrics, offering improved accuracy, scalability, and robustness over existing methods.
Keywords:
Dynamic malware signatures
Malware cascading effect
Malware detection
Multivariate series classification
Performance metrics
Resource utilization metrics
XAI
AI Summary

AI Summary

Key information extracted from the uploaded paper, including a brief overview, abstract, background, key highlights, visual analysis, and future outlook.

Journal

Results in Engineering cover
Results in Engineering
IF:
7.9
Papers:
1.1W
Citations:
1.7W

Organization

A
aristotle university of thessaloniki
Scholars:
2.6W
Papers: 2.0W
Citations: 19