arrow
Return

Extending Memory-Based Obfuscated Malware Detection With Network Behavior

delete2026-02-25
delete0
delete
OA
AI
J
Jhon F. Mercado
J
Josue Genaro Almaraz-Rivera
S
Sergio Armando Gutierrez
J
Jesús Arturo Pérez-Díaz
L
Luis Fletscher
J
Jose Antonio Cantoral-Ceballos
J
Juan Felipe Botero
DOI:10.1109/OJCOMS.2026.3667851delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Obfuscated and fileless malware families evade traditional detection systems by residing exclusively in memory and employing stealthy techniques such as process injection and encrypted communication. Although memory-based detection methods have demonstrated strong performance using host-based features alone, the contribution of network-level information remains underexplored. This study addresses this gap by leveraging the recently released WinMal25 dataset, which comprises approximately 2 TB of ground-truth Windows memory dumps collected under realistic benign activity and obfuscated malicious execution. We extract a small set of socket- and connection-level variables directly from RAM and evaluate their contribution to malware detection using Random Forest and XGBoost classifiers under multiple feature configurations. The experimental results show that network-related structures preserved in memory are highly discriminative on their own and further enhance detection performance when combined with traditional system-level features. These findings demonstrate that communication-related structures preserved in memory constitute a robust and complementary forensic signal, supporting the development of interpretable and generalizable memory-based malware detection systems capable of operating under heavy obfuscation.
Keywords:
Fileless malware
malware detection
memory forensics
network behavior
obfuscated malware
volatility framework

Journal

I
IEEE Open Journal of the Communications Society
IF:
6.1
Papers:
562
Citations:
0

Organization

U
universidad de antioquia
Scholars:
1.3K
Papers: 593
Citations: 2
T
tecnologico de monterrey
Scholars:
530
Papers: 244
Citations: 1
Cited Papers

Cited Papers

A Comprehensive Review on Malware Detection Approaches
err2020-01-01
err263
errOAAI
errAslan, Omer; Samet, Refik
errShare
errSave
A Malware Detection Approach Based on Deep Learning and Memory Forensics
err2023-03-19
err0
errOAAI
errShuhui Zhang; Changdong Hu; Lianhai Wang; Miodrag Mihaljevic; Shujiang Xu; Tian Lan
errShare
errSave
Sentences Based Adversarial Attack on AI-Generated Text Detectors
err2026-02-01
err3
PREAI
errTu, Rongxin; Kang, Xiangui; Tan, Chee Wei; Chi, Chi-Hung; Lam, Kwok-Yan
errShare
errSave
A Perspective on Explainable Artificial Intelligence Methods: SHAP and LIME
err2024-06-27
err9
errOAAI
errSalih, Ahmed M.; Raisi-Estabragh, Zahra; Galazzo, Ilaria Boscolo; Radeva, Petia; Petersen, Steffen E.; Lekadir, Karim; Menegaz, Gloria
errShare
errSave
researcher View more