An Integrated Approach to Malware Identification Based on Dynamic Analysis and Deep Learning
DOI: 10.21293/1818-0442-2025-28-1-108-113
DOI: 10.21293/1818-0442-2025-28-1-108-113
Abstract: The article presents a new approach to malware identification. It is based on the idea of integrating program behavior analysis methods with modern machine learning algorithms. The process includes program disassembly, control flow graph construction, behavioral patterns detection in an isolated environment, metainformation extraction and program classification into 3 classes. The algorithmic basis of the developed approach is an ensemble of graph and hybrid neural networks. The purpose of the graph network is to analyze the control flow graph, and the hybrid network is to analyze static and dynamic features defined by Cockoo Sandbox, as well as assembly code obtained as a result of reverse engineering. The approach based on such an ensemble demonstrates an accuracy of 0.88 in classifying code into legitimate, malicious and APT malware and 0.94 - into legitimate and malicious.
Keywords: malware, APT, static analysis, dynamic analysis, virus
Funding: The study was carried out with the financial support of the Ministry of Science and Higher Education of the Russian Federation as part of the basic part of the state assignment to TUSUR for 2023–2025 (project No. FEWM-2023-0015).
For citation:
Kurtukova A. V. An Integrated Approach to Malware Identification Based on Dynamic Analysis and Deep Learning. Doklady Tomskogo gosudarstvennogo universiteta sistem upravleniya i radioelektroniki, 2025, vol. 28, no. 1, pp. 108–113. DOI: 10.21293/1818-0442-2025-28-1-108-113
Authors and copyright holders:
Executive Secretary of the Editor’s Office
Editor’s Office: 40 Lenina Prospect, Tomsk, 634050, Russia
Phone / Fax: + 7 (3822) 701-582
Viktor N. Maslennikov
Executive Secretary of the Editor’s Office
Editor’s Office: 40 Lenina Prospect, Tomsk, 634050, Russia
Phone / Fax: + 7 (3822) 51-21-21 / 51-43-02