A multimodal Windows malware detection method based on hybrid analysis and graph representations

Pham Thai Bao, Do Thi Thu Hien, Nguyen Tan Cam, Van-Hau Pham · 2024

When Windows becomes the most widely used operating system compared to its counterparts, there is a rising number of attacks targeting this system, in which malicious executable files or malware is one of the most prevalent threats. Hence, verifying the maliciousness of executable files is essential to prevent harmful impacts on the system, leading to numerous research efforts to propose novel Windows malware detection methods. Although machine learning (ML) or deep learning (DL) has offered promising results in detecting malware, existing works still have limitations, such as using static analysis methods or only leveraging a piece of specific information to recognize maliciousness. This may reduce the effectiveness of the detector while dealing with malware that uses evasion techniques. Therefore, in this paper, we present a multimodal approach for Windows malware detection based on various pieces of information extracted by a hybrid analysis process. While the PE header information plays the role of static features, we aim to extract a dynamic control flow graph (CFG). We utilize the dynamic analysis method to create CFG, through the symbolic execution approach, with the intent that our work can be applied to certain malware environments that may undergo code obfuscation. The experiments on approximately 24,000 PE files in multiple datasets prove the effectiveness of our work, with an accuracy of 99.25% in distinguishing malware and benign files.

Read the paper · More papers on PaperTik