Portable Executable Malware Classifier Using Long Short Term Memory and Sophos-ReversingLabs 20 Million Dataset

Julianne Alyson I. Diaz, Argel Alejandro Bandala · TENCON 2021 - 2021 IEEE Region 10 Conference (TENCON) · 2021

This research paper proposes the Utilization of Long Short Term Memory(LSTM) paired with LightGBM in Portable Executable (PE) Malware Classification, which will be trained and tested with the Sophos-ReversingLabs 20 Million Dataset (SoReL-20M). PE files are regular executable, object codes, and Dynamic Link Libraries (DLLs) files used commonly in Windows operating systems in 32-bit and 64-bit versions. Problems, when PE malware is not detected, is its ability to install rootkits, worms, trojans and etc. Current development in PE malware detection suggests signature-based detection. Although most studies produce high accuracy, it is not always applicable to all scenarios, especially on zero-day attacks. Other studies in malware detection suggest the use of a non-signature-based approach, hence the proposed method of utilization of LSTM for the research. Due to the large number of SoReL-20M dataset to be processed, LightGBM will be used to reduce its impact on the resources.

Read the paper · More papers on PaperTik