<p>Malware poses an escalating threat to digital systems by evading detection and compromising critical data, particularly in network environments and memory. Despite extensive research in this area, advanced malware effectively uses obfuscation techniques to bypass traditional detection methods. This study proposes a novel hybrid approach that combines an innovative preprocessing stage with a metaheuristic-based deep learning architecture to effectively detect hidden malicious software. Specifically, one-dimensional (1D) structured memory dump data are transformed into three distinct two-dimensional (2D) barcode images: Aztec, Data Matrix, and QR, enabling both data obfuscation and the utilization of powerful 2D convolutional neural networks (CNNs). These barcode datasets are trained using the MobileNetV2 architecture, enhanced with a novel type-based fully connected layer that extracts class feature sets. To further improve classification performance, the Sand Cat Swarm (SCS) optimization algorithm is employed for feature selection, reducing redundancy and emphasizing discriminative features. The method was evaluated on a balanced memory dataset containing benign software, ransomware, spyware, and trojans, with equal subclass representation to preserve behavioral diversity. Experimental results demonstrate that the proposed approach achieves an accuracy of 99.42% using the Softmax and maintains 99.30% accuracy under 5-fold cross-validation, confirming its robustness and generalizability. The main contributions of this work include transforming 1D memory analysis data into 2D barcode images for CNN-based processing, designing a type-based feature extraction layer within MobileNetV2, and integrating the SCS optimization algorithm for enhanced feature selection. Together, these innovations provide a scalable, accurate, and secure solution for detecting stealthy malware in memory environments.</p> Graphical Abstract <p></p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

A Novel Approach to Malware Detection: Converting Hardware Memory Data to 2D Barcodes Using Mobile Networks

  • Mesut Toğaçar

摘要

Malware poses an escalating threat to digital systems by evading detection and compromising critical data, particularly in network environments and memory. Despite extensive research in this area, advanced malware effectively uses obfuscation techniques to bypass traditional detection methods. This study proposes a novel hybrid approach that combines an innovative preprocessing stage with a metaheuristic-based deep learning architecture to effectively detect hidden malicious software. Specifically, one-dimensional (1D) structured memory dump data are transformed into three distinct two-dimensional (2D) barcode images: Aztec, Data Matrix, and QR, enabling both data obfuscation and the utilization of powerful 2D convolutional neural networks (CNNs). These barcode datasets are trained using the MobileNetV2 architecture, enhanced with a novel type-based fully connected layer that extracts class feature sets. To further improve classification performance, the Sand Cat Swarm (SCS) optimization algorithm is employed for feature selection, reducing redundancy and emphasizing discriminative features. The method was evaluated on a balanced memory dataset containing benign software, ransomware, spyware, and trojans, with equal subclass representation to preserve behavioral diversity. Experimental results demonstrate that the proposed approach achieves an accuracy of 99.42% using the Softmax and maintains 99.30% accuracy under 5-fold cross-validation, confirming its robustness and generalizability. The main contributions of this work include transforming 1D memory analysis data into 2D barcode images for CNN-based processing, designing a type-based feature extraction layer within MobileNetV2, and integrating the SCS optimization algorithm for enhanced feature selection. Together, these innovations provide a scalable, accurate, and secure solution for detecting stealthy malware in memory environments.

Graphical Abstract