A Hybrid Deep Learning Based Approach for Windows Malware Detection Using Static Feature Analysis
Main Article Content
Abstract
The modern computing infrastructures have continued to be greatly infected by malware, mostly owing to the increase in obfuscated code patterns and zero day exploits. Traditional signature based detection systems are ineffective when it comes to extending the challenge of such updated types of malwares. This paper suggests a hybrid malware detection system that would jointly utilize both the static features analysis and a deep learning classifier to enhance the detection rate and malware detection resilience. Through a combination of complementary methodological advantages, the methodology purports to overcome the weaknesses of a pure signature based or heuristic approach. The model takes high dimensional statistic attributes out of windows portable executives (PE) files and then passes such representations through a deep neural network that justifies benign and malignant samples. The feature space is designed as a fixed space, such that the structural, opcode, and metadata features that are useful to high quality classification are represented. The EMBER 2018 benchmark data is tested empirically. The hybrid model obtains the overall accuracy of 96.32 Percent and the area under the receiver operating characteristic curve (AUC) of 0.963, which proves a high level of discriminating power and shows the viability of deploying the model to the large-scale malware detections.....
Article Details

This work is licensed under a Creative Commons Attribution-NonCommercial-ShareAlike 4.0 International License.
References
AV-TEST Institute, “Malware statistics and trends,” 2023. Available: https://www.av-test.org
M. Christodorescu and S. Jha, “Static analysis of executables to detect malicious patterns,” Proc. 12th USENIX Security Symposium, Washington, DC, USA, 2003, pp. 169–186.
E. Gandotra, D. Bansal, and S. Sofat, “Malware analysis and classification: A survey,” Journal of Information Security, vol. 5, no. 2, pp. 56–64, 2014.
Y. Ye, T. Li, Q. Jiang, and Y. Wang, “CIMDS: Adapting postprocessing techniques of associative classification for malware detection,” IEEE Trans. Systems, Man, and Cybernetics, vol. 40, no. 2, pp. 298–307, 2010.
S. Shabtai, R. Moskovitch, Y. Elovici, and C. Glezer, “Detection of malicious code by applying machine learning classifiers on static features,” Security Informatics, vol. 1, no. 1, pp. 1–18, 2012.
J. Saxe and K. Berlin, “Deep neural network based malware detection using two dimensional binary program features,” Proc. IEEE Malware, 2015, pp. 11–20.
R. Vinayakumar et al., “Deep learning approach for intelligent intrusion detection system,” IEEE Access, vol. 7, pp. 41525–41550, 2019.
S. Garg, R. S. Bali, and S. K. Khatri, “A hybrid malware detection framework using static and dynamic analysis,” Proc. IEEE Int. Conf. on Computing, Communication and Automation, 2020.
A. Baldangombo, J. R. Tapamo, and S. O. Oladele, “Hybrid malware detection using machine learning techniques,” Computers & Security, vol. 105, 2021.
H. S. Anderson and P. Roth, “EMBER: An open dataset for training static PE malware machine learning models,” arXiv preprint arXiv:1804.04637, 2018.
J. Z. Kolter and M. A. Maloof, “Learning to detect and classify malicious executables in the wild,” Journal of Machine Learning Research, vol. 7, pp. 2721–2744, 2006.
Y. LeCun, Y. Bengio, and G. Hinton, “Deep learning,” Nature, vol. 521, pp. 436–444, 2015