arrow
Return

Effective One-Class Classifier Model for Memory Dump Malware Detection

delete2023-01-17
delete22
delete
OA
AI
M
Mahmoud Al-Qudah
Z
Zein Ashi
M
Mohammad Alnabhan
Q
Qasem Abu Al‐Haija *
DOI:10.3390/jsan12010005delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Malware complexity is rapidly increasing, causing catastrophic impacts on computer systems. Memory dump malware is gaining increased attention due to its ability to expose plaintext passwords or key encryption files. This paper presents an enhanced classification model based on One class SVM (OCSVM) classifier that can identify any deviation from the normal memory dump file patterns and detect it as malware. The proposed model integrates OCSVM and Principal Component Analysis (PCA) for increased model sensitivity and efficiency. An up-to-date dataset known as MALMEMANALYSIS-2022 was utilized during the evaluation phase of this study. The accuracy achieved by the traditional one-class classification (TOCC) model was 55%, compared to 99.4% in the one-class classification with the PCA (OCC-PCA) model. Such results have confirmed the improved performance achieved by the proposed model.
Keywords:
Novelty-class
One-class SVM (OCSVM)
Memory dump
Malware
Principal Component Analysis (PCA)
Dimensionality Reduction

Journal

Journal of Sensor and Actuator Networks cover
Journal of Sensor and Actuator Networks
IF:
4.2
Papers:
606
Citations:
1.6K

Organization

P
Princess Sumaya University for Technology
Scholars:
406
Papers: 375
Citations: 174