FORTUNATE: Decrypting and Classifying Malware by Variable Length Instruction Sequences
César Augusto Borges de Andrade, Geraldo P. Rocha Filho, Rodolfo I. Meneguette, João Paulo A. Maranhão, Ricardo Sant'Ana, Júlio César Duarte, André Luiz Marques Serrano, Vinícius P. Gonçalves · 2024
After identifying an artifact as malware, the additional challenge arises of correctly classifying it into a specific family. This raises the challenge of classifying malware amid growing complexity and the increasing volume of cyber threats. Therefore, we introduce FORTUNATE, a framework that employs variable-length instruction sequences to classify malware more efficiently and accurately, focusing on real and active malware. By introducing effective methods for extracting opcodes and their representation in the smallest possible vectors, FORTUNATE surpasses the limitations of previous approaches, enabling the correct identification of malware in their respective families, while avoiding redundancies in the data. The results achieved with FORTUNATE demonstrate advances in both precision and computational efficiency, consolidating it as a significant contribution to the field of cybersecurity.