Malware refers to a broad spectrum of software that tries to gain unauthorized access to data and use it for destructive purposes, potentially resulting in data loss, financial theft, and other serious consequences. Traditional forensic methods are often inadequate for detecting memory-resident malware that lacks disk traces, which may result in undetected threats. This project addresses this gap by proposing a federated learning approach for analyzing memory dumps to detect and categorize malware. The methodology leverages federated learning to train a robust model on distributed client data while preserving privacy. Utilizing a sequential classifier enhanced by RMSprop optimization, our methodology emphasizes privacy-preserving data training across distributed clients. The model employs a Long Short-Term Memory (LSTM) neural network to analyze sequential data, effectively identifying key indicators of malicious activity. By analyzing memory dumps for indicators of malicious activity, this approach aims to contribute to a robust and privacy-preserving method for detecting memory-based malware. The process involves data profiling, feature selection, model building, and training to identify key indicators of malicious activity in memory. By addressing these key issues, it aims to offer a robust method for analyzing and detecting memory-based malware.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

A Novel Federated Learning Approach to Memory-Based Malware Detection Model Using RMS Propagation and Sequential Classifier

  • M. Eswar,
  • P. Athibhan,
  • B. Darshni,
  • P. Vijayakumar

摘要

Malware refers to a broad spectrum of software that tries to gain unauthorized access to data and use it for destructive purposes, potentially resulting in data loss, financial theft, and other serious consequences. Traditional forensic methods are often inadequate for detecting memory-resident malware that lacks disk traces, which may result in undetected threats. This project addresses this gap by proposing a federated learning approach for analyzing memory dumps to detect and categorize malware. The methodology leverages federated learning to train a robust model on distributed client data while preserving privacy. Utilizing a sequential classifier enhanced by RMSprop optimization, our methodology emphasizes privacy-preserving data training across distributed clients. The model employs a Long Short-Term Memory (LSTM) neural network to analyze sequential data, effectively identifying key indicators of malicious activity. By analyzing memory dumps for indicators of malicious activity, this approach aims to contribute to a robust and privacy-preserving method for detecting memory-based malware. The process involves data profiling, feature selection, model building, and training to identify key indicators of malicious activity in memory. By addressing these key issues, it aims to offer a robust method for analyzing and detecting memory-based malware.