Malware detection using Memory Image Visualization

Bhukya Krishna Priya, Bhukya Krishna Naick, B. Shameedha Begum, N Ramasubramanian · 2025

In recent years, malware detection is a critical task in ensuring the security of computer systems and networks. Traditional methods such as static and dynamic malware detection often rely on signature-based approaches that are limited in their ability to detect new and unknown malware variants. The memory forensic analysis has emerged as a promising technique for malware detection as some malware exist in the system are undetected from tradition detection methods by hiding into volatile memory. The existing techniques proposed by researchers use the concept of memory forensics, extract the meaningful information from the volatile memory and convert it into images for detecting the malware. Some of the proposed model detects and classify the malware variants, but lacks in classifying data with few data images. Few models take large datasets for training, long computation time and fast but lack in consistency and performance. In the proposed method, the visualized form of volatile memory’s (RAM’s) content i.e., images are used for malware detection and classification. The contents of RAM are collected from an isolated virtual system where malware is run. The RAM contents are converted into desired image file by denoising the images for better and accurate computation and extraction of feature. The proposed method proposes a machine-learning model with light and fast computation for malware detection and classification using memory images. The proposed model improves the accuracy by 0.5% and precision by 1%.

Read the paper · More papers on PaperTik