Toward an Ensemble Behavioral-based Early Evasive Malware Detection Framework
Faitour. A. Aboaoja, Anazida Binti Zainal, Fuad Abdulgaleel Abdoh Ghaleb, Bander Ali Saleh Al‐rimy · 2021
Recently malware threats are evolved to be the most cyber security threats. Because of obfuscation and evasion techniques, malware has become more sophisticated in terms of multiple variants representing the same malware function and rapidly evading existing detection approaches. The current solutions extracted the entire data without considering the unrepresentative data that belongs to evasive malware when they recognize that they are executed in controlled environments. In addition, obfuscation techniques such as dead code insertion and reordering instructions aim to produce irrelevant data and make the previous approaches based on names, frequencies, and sequences of the extracted data suffer from low detection rate. To this end, this paper proposes a framework for building an effective early malware detection model that can protect systems and data from evasive malware attacks. Predetermined evasion techniques list is used to extract the most malware behaviors representative data. The Pearson correlation coefficient (r) method is proposed to calculate the correlation between the extracted data to overcome the problem of irrelevant data.