Aug 2026· International Conference Computational Vision and Bio Inspired Computing· pp. 908-915· 0 citations· 21 references
Abstract
Fileless Malware is one of the fastest-evolving and hardest-to-detect types of malware. The malware resides solely within System Memory and never uses typical files as its payload. Fileless malware can utilize legitimate software like PowerShell and WMI, along with LOLBins to remain completely hidden in System Memory, eliminating any digital footprint on the physical hard drive, thus allowing it to elude detection by Signature-based Antivirus systems. In this paper we present a Hybrid Detection Framework that utilizes both Machine Learning and Memory Forensics for detecting malicious activity that operates in a file-less manner. Volatility extracts relevant data from the memory of an active system, creating structured dataset(s) containing Process Behavior, DLL injection Activity, Network Indicators and Script Execution Tracing. Multiple Machine Learning Models have been trained, including Random Forest and XG Boost to discern malicious from benign behavior. Our proposed Hybrid Model provides significant improvements over existing methods for file-less malware detection while reducing False Positives.
Current malware detection systems face obstacles because modern malware operates with increasingly complex patterns which signature-based detection systems cannot identify. Malware developers use obfuscation and encryption and polymorphism techniques to protect their malware from detection by security systems. Memory f...
A. Bhonde, Sanjana Yadav, Shashank Kutty et al.· International Conference on...· 0 citations
An efficient stacked-ensemble model that estimates how likely a given executable is to be malicious and is compared against recent malware research/types are compared and identified for future research work/area.
Deepak Singh Rana, Sushil Chandra Dimri· International journal of com...· 0 citations
The rapid mutation and obfuscation techniques employed by modern polymorphic botnets create a highly dynamic and non-stationary distribution of malware signatures, rendering traditional detection algorithms obsolete. This paper addresses the challenge of identifying such evasive threats by proposing a machine learning-...
Andrii Holovatiuk, Oleg Savenko· Automation, Control, and Inf...· 0 citations
Cyber-attacks are causing billionaires losses in ascending order. Then, our goal is to detect malicious behavior of the suspect executable files, preventively, even previously the file be executed by the client. In this current paper, we propose an antivirus to detect malware utilizing mELM (Morphological Extreme Learn...
Sidney M. Lopes-Lima, Heverton K. de L. Silva, J. H. da S. Luz et al.· SN Computer Science· 0 citations
This work presents Replicant, a deep reinforcement learning framework that learns the realistic task of evasion under a strict label-only black-box threat model and demonstrates that learning the task of evasion not only results in stronger attack performance but provides a better signal for hardening malware detectors...
Shae McFadden, Ilias Tsingenopoulos, Mario D'Onghia et al.· 0 citations