Analysis of the Zero-Day Detection of Metamorphic Malware

dc.contributor.authorGulmez, Sibel
dc.contributor.authorKakisim, Arzu Gorgulu
dc.contributor.authorSogukpinar, Ibrahim
dc.date.accessioned2025-05-10T15:23:57Z
dc.date.issued2024
dc.departmentİstanbul Medeniyet Üniversitesi
dc.description9th International Conference on Computer Science and Engineering, UBMK 2024 -- 26 October 2024 through 28 October 2024 -- Antalya -- 204906
dc.description.abstractMetamorphic malware is a kind of malware that modifies its source code with each new infection. The source code modification is carried out by a morphing engine that applies particular metamorphism techniques, which allows each metamorphic variant of a malware to have a unique signature, disabling signature-based detection models. Therefore, behavioral analysis becomes essential for malware detection. A behavioral analysis-based detection model trained on data from a specific morphing engine can detect new metamorphic variants produced by that same engine. However, these models often struggle with samples generated by different morphing engines, i.e. zero-day metamorphic malware. Due to the concept drift problem, which is also challenging for many classification and detection problems, many existing malware detection methods tend to underperform when tested on a dataset different from the malware dataset they were trained on. In this study, we aim to explore this issue and examine potential solutions for zero-day metamorphic malware detection using different approaches based on static analysis along with machine and deep learning techniques. We also utilize ransomware samples in order to show their contribution to metamorphic malware detection. Experiments we conducted demonstrate that zero-day metamorphic malware can be effectively detected using a straightforward and efficient model that leverages opcode sequences. © 2024 IEEE.
dc.description.sponsorshipGebze Teknik Üniversitesi, (2022-A-113-03)
dc.identifier.doi10.1109/UBMK63289.2024.10773421
dc.identifier.endpage736
dc.identifier.isbn979-835036588-7
dc.identifier.scopus2-s2.0-85215504142
dc.identifier.scopusqualityN/A
dc.identifier.startpage731
dc.identifier.urihttps://doi.org/10.1109/UBMK63289.2024.10773421
dc.identifier.urihttps://hdl.handle.net/20.500.14730/6553
dc.indekslendigikaynakScopus
dc.language.isoen
dc.publisherInstitute of Electrical and Electronics Engineers Inc.
dc.relation.ispartofUBMK 2024 - Proceedings: 9th International Conference on Computer Science and Engineering
dc.relation.publicationcategoryKonferans Öğesi - Uluslararası - Kurum Öğretim Elemanı
dc.rightsinfo:eu-repo/semantics/closedAccess
dc.snmzKA_Scopus_20250302
dc.subjectmetamorphic malware; ransomware; static analysis; zero-day malware detection
dc.titleAnalysis of the Zero-Day Detection of Metamorphic Malware
dc.typeConference Object

Dosyalar

Orijinal paket

Listeleniyor 1 - 1 / 1
Yükleniyor...
Küçük Resim
İsim:
6553
Boyut:
318.03 KB
Biçim:
Adobe Portable Document Format