상세 보기
Deep Learning Framework for Fileless Malware Detection via Volatile Memory Forensics
- Rai, Andri;
- Rai, Somesh;
- Im, Eul Gyu
SCOPUS
0초록
Traditional malware leaves persistent traces on storage drives; in contrast, fileless malware operates entirely within volatile memory (RAM), leveraging native system utilities to evade conventional antivirus mechanisms. This study addresses this critical cybersecurity challenge by proposing a deep learning-based framework for automated forensic analysis of memory dumps using the CIC-MalMem-2022 dataset. A structured pre-processing pipeline was implemented to extract and standardize memory artifacts prior to model training. The performance of Convolutional Neural Networks (CNN), Long Short-Term Memory (LSTM), Recurrent Neural Networks (RNN), and Deep Neural Networks (DNN) was evaluated for both binary and multi-class classification to distinguish benign processes from obfuscated malicious activities. Experimental results demonstrate that deep learning architectures significantly outperform traditional machine learning approaches in detecting evasive threats. The proposed CNN and LSTM models achieved a testing accuracy of 99.99% in binary classification and up to 99.97% in multi-class malware family categorization (Spyware, Ransomware, Trojan), confirming the robustness and effectiveness of neural network-based memory forensics in defending modern computing environments against sophisticated fileless cyber-attacks.
키워드
- 제목
- Deep Learning Framework for Fileless Malware Detection via Volatile Memory Forensics
- 저자
- Rai, Andri; Rai, Somesh; Im, Eul Gyu
- 발행일
- 2026-04
- 유형
- Conference paper
- 저널명
- Proceedings of 9th International Conference on Inventive Computation Technologies, ICICT 2026
- 페이지
- 887 ~ 895