This paper investigates a unified behavioral analysis framework that combines temporal and structural representations of Windows API call sequences: a sequential view based on learned API n-gram representations and a Bidirectional LSTM (BiLSTM) encoder, a structural view derived from the API transition graph, and a multi-head attention fusion of the two.
Background: Metamorphic malware is among the most persistent adversarial challenges in cybersecurity: it rewrites its own instruction stream on every propagation, preserving functional semantics while presenting a syntactically distinct binary that defeats signature-based and many learning-based detectors. Methods: We...
Víctor Manuel González-Gorrín, Josep Prieto-Blázquez· Journal of Cybersecurity and...· 0 citations
The study introduces an innovative approach of deep learning-based hybrid system to classify malware based on its real-time detection using a novel architecture called “Gated Convolutional Embedded Convolutional Network - Bidirectional Long Short-Term Memory (GCE-CNN-BiLSTM)” that integrates both static and dynamic se...
Nishok Kumar S, L. Sheela· Adolescência e Saúde· 0 citations
Recent rapid increases in sophisticated malware have severely challenged traditional signature-based security systems, particularly in their ability to recognize zero-day and polymorphic threats. This paper introduces “DeepGuard,” an AI/Machine-Learning-powered behavioral malware detection framework built around the an...
Vidya Gavekar, Amar Anant Shinde, S. Lodha et al.· International Conference on...· 0 citations
Concept drift, driven by the rapid evolution of Android malware, severely degrades the performance of machine learning detectors. Current adaptation strategies are often reactive, responding only after performance has dropped and imposing a significant manual annotation burden, or they are proactive but rely on unstabl...
Han Chen, Han-Chen Wang, Hong-Mei Chen et al.· 0 citations
Signature-based malware detection is undermined by obfuscation and packing, motivating dynamic analysis of Application Programming Interface (API) call sequences. Existing image-based classifiers reach high accuracy but rarely explain why a sample belongs to a given family. In this paper, our goal is not to maximize cl...
A Transformer-based malware detection approach named MalBERT-Temporal that reshapes the 2,381-dimensional BODMAS PE feature vector into 16 contiguous feature-group tokens and then processes these tokens with Transformer encoder layers employing multi-head self-attention to model interactions among all tokens is introdu...
Manar Alanazi, Israa Alsiyat· International Journal of Adv...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.