A Lightweight Obfuscated Malware Multi-class Classifier for IoT Using Machine Learning

William S. Cassel, Nahid Ebrahimi Majd · 2024

The rapidly growing number of obfuscated malware attacks in the past few years has emerged as a significant threat for organizations and individuals, demanding prompt action to develop systems that accurately detect these attacks to block them or mitigate their impacts. These types of malwares use obfuscation techniques to hide their malicious functionalities from intrusion detection systems, which makes their detection more complicated than regular malwares. Most of the obfuscated malware detection systems primarily focus on binary classification. The existing multi-class classification methods mainly have used CNN-based deep learning to improve the model's accuracy. However, this approach is not suitable for resource constrained network nodes, such as IoT devices, which are widely used on the Internet to monitor and control different environments. To tackle this issue, in this paper, we propose a lightweight model that accurately and efficiently classifies benign traffic vs. different classes of obfuscated malwares. Our proposed model uses a hybrid method of SMOTE oversampling to synthetically create training records for the minority classes in combination with undersampling the majority class via Tomek Links algorithm to increase the model's performance in malware classification. W applied this hybrid data augmentation technique to our training dataset extracted from CIC-MaIMem2022 dataset to build a Random Forest model. Our experimental results demonstrated that the proposed model outperforms the state-of-the-art with 87.1 % accuracy in classifying obfuscated malwares.

Read the paper · More papers on PaperTik