Optimizing Malware Detection in Virtual Cloud Environments Using Hybrid Machine Learning Approach
摘要
Cloud environments are increasingly becoming prime targets for malicious activities due to their dynamic nature and growing adoption across industries. Protecting these virtualized infrastructures from sophisticated threats, especially those targeting malware behavior in memory, presents significant challenges. While machine learning (ML) has been increasingly adopted for cloud security, existing approaches often rely on standalone models or shallow anomaly detection techniques that fail to address the behavioral complexity of memory-resident malware in virtualized environments. Traditional signature-based methods and basic ML models struggle to detect novel threats that evade static analysis, particularly in dynamic cloud infrastructures. This research proposes a novel hybrid approach that focuses on the behavior of malware within cloud virtual environments, leveraging dynamic memory analysis and advanced ensemble learning to overcome the limitations of prior ML solutions. By utilizing the MalMem2022 dataset, we have developed a robust malware detection model that integrates advanced machine learning techniques to accurately identify and classify malicious activities. The proposed method achieved an accuracy of 99.12%, precision of 99.27%, recall of 99.86%, and an F1-score of 99.39%, demonstrating its effectiveness in handling the complex, ever-evolving threat landscape of cloud environments. The results underscore the potential of memory-based analysis and machine learning in enhancing cloud security by detecting malware with high precision and minimal false positives, aligning with the pressing need for resilient cybersecurity in cloud infrastructures.