Return
Extending Memory-Based Obfuscated Malware Detection With Network Behavior
DOI:10.1109/OJCOMS.2026.3667851.png)
Abstract
En 中文
Obfuscated and fileless malware families evade traditional detection systems by residing exclusively in memory and employing stealthy techniques such as process injection and encrypted communication. Although memory-based detection methods have demonstrated strong performance using host-based features alone, the contribution of network-level information remains underexplored. This study addresses this gap by leveraging the recently released WinMal25 dataset, which comprises approximately 2 TB of ground-truth Windows memory dumps collected under realistic benign activity and obfuscated malicious execution. We extract a small set of socket- and connection-level variables directly from RAM and evaluate their contribution to malware detection using Random Forest and XGBoost classifiers under multiple feature configurations. The experimental results show that network-related structures preserved in memory are highly discriminative on their own and further enhance detection performance when combined with traditional system-level features. These findings demonstrate that communication-related structures preserved in memory constitute a robust and complementary forensic signal, supporting the development of interpretable and generalizable memory-based malware detection systems capable of operating under heavy obfuscation.
Keywords:
Fileless malware
malware detection
memory forensics
network behavior
obfuscated malware
volatility framework
Journal
I
IF:
6.1
Papers:
562
Citations:
0

