arrow
Return

Obfuscated Privacy Malware Classifiers Based on Memory Dumping Analysis

delete2024-01-01
delete4
delete
OA
AI
D
David Cevallos-Salas *
F
Felipe Grijalva
J
José Antonio Estrada
D
Diego S. Benítez
R
Roberto Andrade
DOI:10.1109/ACCESS.2024.3358840delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Malware targeting user privacy has seen a surge in recent times, attributed to evolving global regulations and the boost of electronic commerce and online services. Moreover, recognizing privacy malware that employs obfuscation as evasion mechanism presents a major challenge due to its dynamics, resilience, and polymorphism at runtime, necessitating the application of forensic techniques such as memory dumping analysis in order to reveal suitable patterns and behaviors that enable its subsequent detection and classification. In this paper, we present three obfuscated privacy malware classifiers trained on the CIC-MalMem-2022 dataset. These solutions include a binary classifier to distinguish benign from malicious samples using logistic regression (LR), a multiclass classifier that further categorizes benign, spyware, ransomware, and trojan horse obfuscated privacy malware; and a more detailed multiclass classifier capable of discriminating benign samples from fifteen specific obfuscated privacy malware families. Multiclass classifiers were built using several traditional machine learning algorithms and a novel Deep Neural Network (DNN). We applied the Synthetic Minority Oversampling Technique (SMOTE) to address data imbalances. In particular, our results demonstrate that DNN outperforms traditional machine learning algorithms, yielding statistically significant improvements in key metrics. These achievements reach practical thresholds, suggesting the potential for enhanced malware protection systems. The dataset and all the coding files required for experiments reproducibility are publicly available at https://github.com/dcevallossalas/PrivacyMalwareClassifiers.
Keywords:
Malware
Privacy
Data privacy
Ransomware
Measurement
Machine learning algorithms
Behavioral sciences
malware
obfuscation
classifier
memory dumping
CIC-MalMem-2022
SMOTE
ransomware
spyware
trojan horse

Journal

IEEE Access cover
IEEE Access
IF:
3.6
Papers:
9.8W
Citations:
29.4W

Organization

E
escuela politecnica nacional ecuador
Scholars:
928
Papers: 945
Citations: 1
Universidad San Francisco de Quito cover
Universidad San Francisco de Quito
Scholars:
1.8K
Papers: 1.8K
Citations: 1.3K