An Integrated Approach to Malware Identification Based on Dynamic Analysis and Deep Learning

DOI: 10.21293/1818-0442-2025-28-1-108-113

Download article in PDF format

JATS xml

Abstract: The article presents a new approach to malware identification. It is based on the idea of integrating program behavior analysis methods with modern machine learning algorithms. The process includes program disassembly, control flow graph construction, behavioral patterns detection in an isolated environment, metainformation extraction and program classification into 3 classes. The algorithmic basis of the developed approach is an ensemble of graph and hybrid neural networks. The purpose of the graph network is to analyze the control flow graph, and the hybrid network is to analyze static and dynamic features defined by Cockoo Sandbox, as well as assembly code obtained as a result of reverse engineering. The approach based on such an ensemble demonstrates an accuracy of 0.88 in classifying code into legitimate, malicious and APT malware and 0.94 - into legitimate and malicious.

Keywords: malware, APT, static analysis, dynamic analysis, virus

Funding: The study was carried out with the financial support of the Ministry of Science and Higher Education of the Russian Federation as part of the basic part of the state assignment to TUSUR for 2023–2025 (project No. FEWM-2023-0015).

For citation:
Kurtukova A. V. An Integrated Approach to Malware Identification Based on Dynamic Analysis and Deep Learning. Doklady Tomskogo gosudarstvennogo universiteta sistem upravleniya i radioelektroniki, 2025, vol. 28, no. 1, pp. 108–113. DOI: 10.21293/1818-0442-2025-28-1-108-113

Authors and copyright holders:

  • Kurtukova A. V. , Tomsk State University of Control Systems and Radioelectronics (Tomsk, Russia)

  • 1. Tsfaty C., Fire M. Malicious Source Code Detection Using Transformer. arXiv preprint, arXiv: 2209.07957, 2022. Available at: https://arxiv.org/abs/2209.07957, free (Accessed: February 09, 2025)
  • 2. The Backstabber’s Knife Collection. Available at: https://dasfreak.github.io/Backstabbers-Knife-Collection, free (Accessed: February 09, 2025).
  • 3. Navid S.Z., Dey P., Hasan S., Ali M. Static Detection of Malicious Code in Programs Using Semantic Techniques. 2020 11th International Conference on Electrical and Computer Engineering (ICECE), 2020, pp. 327–330. DOI: 10.1109/ICECE51571.2020.9393121.
  • 4. OWL2. Available at: https://www.w3.org/TR/owl2-overview, free (Accessed: February 09, 2025).
  • 5. Klein M., Krupka D., Winter C., Gergeleit M., Martin L. Using Pre-trained Transformers to Detect Malicious Source Code Within JavaScript Packages. Informatik, Lecture Notes in Informatics (LNI), 2024, pp. 529–538. DOI: 10.18420/inf2024.
  • 6. Bukhanov D.G., Sulokhin D.V. [Detection of malware based on the classification of source code graphs]. Proceedings of TUSUR University, 2018, vol. 21 no. 3, pp. 30–34. DOI: 10.21293/1818-0442-2018-21-3-30-34 (in Russ.).
  • 7. Virus Total. Available at: https:// www.virustotal.com, free (Accessed: February 09, 2025).
  • 8. Malware Bazaar. Available at: https:// bazaar.abuse.ch, free (Accessed: February 09, 2025).
  • 9. Rokon O.F., Islam R., Darki A., Papalexakis E.E., Faloutsos M. SourceFinder: Finding Malware Source-Code from Publicly Available Repositories. arXiv preprint, arXiv: 2005.14311, 2020. Available at: https://arxiv.org/abs/2005.14311 (Accessed: February 09, 2025).
  • 10. Kaggle. Available at: https://www.kaggle.com, free (Accessed: February 09, 2025).
  • 11. Cyber Science Lab. APT Malware dataset. Available at: https://cybersciencelab.com/advanced-persistent-threat-aptmalware-dataset, free (Accessed: February 09, 2025).
  • 12. Kurtukova A., Romanov A., Shelupanov A. Source Code Authorship Identification Using Deep Neural Networks. Symmetry, 2020, vol. 12, 2044. DOI:10.3390/sym12122044.
  • 13. Kurtukova A., Romanov A., Fedotova A., Shelupanov A. Complex Cases of Source Code Authorship Identification Using a Hybrid Deep Neural Network. Future Internet, 2022, vol. 14, 287. DOI: 10.3390/fi14100287.
  • 14. Kurtukova A., Romanov A., Shelupanov A. [Development of a methodology for identifying the authorship of binary and disassembled program codes based on an ensemble of modern natural language processing methods]. Proceedings of TUSUR University, 2023, vol. 26, no. 4, pp. 53–60. DOI: 10.21293/1818-0442-2023-26-4-53-60. (In Russ.).
  • 15. Cockoo Sandbox. Available at: https://cuckoosandbox.org/index.html, free (Accessed: February 09, 2025).
  • 16. IDA Pro. Available at: https://hex-rays.com/ida-pro, free (Accessed: February 09, 2025).
  • 17. PyTorch Geometrics. Available at: https://pytorch-geometric.readthedocs.io, free (Accessed: February 09, 2025).
  • 18. Kurtukova A.V., Romanov A.S. Sistema dlya identifikacii avtora iskhodnogo koda programmy «CoDEtective» [System for identifying the author of the source code of the program «CoDetective»]. Rosreestr RF, no. 2021667210, 2021.
Editorial office address

Executive Secretary of the Editor’s Office

 Editor’s Office: 40 Lenina Prospect, Tomsk, 634050, Russia

  Phone / Fax: + 7 (3822) 701-582

  journal@tusur.ru

 

Viktor N. Maslennikov

Executive Secretary of the Editor’s Office

 Editor’s Office: 40 Lenina Prospect, Tomsk, 634050, Russia

  Phone / Fax: + 7 (3822) 51-21-21 / 51-43-02

Subscription for updates