Performance Comparison of Recurrent Neural Networks for Metamorphic Malware
Shubh Mittal, Tisha Chawla, Jay Jajoo, Muskan Bansal, Harsha Parashar, D. Ruby · 2023
Metamorphic malware remains a significant challenge in the field of information security as it constantly changes its code and structure, utilizing sophisticated methods to evade detection by antivirus software. This necessitates advanced techniques such as machine learning and deep learning algorithms to effectively detect it. However, the major hurdles lie in the lack of a comprehensive dataset for training algorithms and the continuous evolution of metamorphic malware. To bridge this research gap, a deep learning-based method is proposed that employs bidirectional LSTM (BiLSTM) to detect metamorphic malware based on attack vectors. A comparative analysis is conducted of BiLSTM's performance against other recurrent neural networks (RNNs) such as long short-term memory (LSTM), gated recurrent units (GRU), and a hybrid model of BiLSTM and GRU. The models were trained using a dataset comprising eight categories of metamorphic malware. The results demonstrate that BiLSTM surpasses other RNNs, achieving the highest accuracy of 93.25% compared to 93.20% for LSTM, 91.90% for GRU, and 86.41% for the hybrid model. The use of the outer activation function, Linear, and the inner activation function, SoftSign, in conjunction with the Adam optimizer, significantly contributed to this achievement. The proposed approach has the potential to greatly enhance current malware detection techniques and improve the overall security of computer systems. Furthermore, it can be extended to address other types of malware and cyber threats. By overcoming the challenges of limited training datasets and the ever-evolving nature of metamorphic malware, this research offers practical advantages, including enhanced threat detection capabilities, reduced false positives, and increased system security.