BERT-Cuckoo15: A Comprehensive Framework for Malware Detection Using 15 Dynamic Feature Types

dc.contributor.authorRabadi, Dima
dc.contributor.authorY. Loo, Jia
dc.contributor.authorG. Teo, Sin
dc.date.accessioned2024-12-26T21:04:43Z
dc.date.available2024-12-26T21:04:43Z
dc.date.issued2025-01-07
dc.description.abstractMalware detection presents significant challenges due to the need to select features from diverse data sources, such as system calls and registry keys, impacting model accuracy. Existing techniques often rely on a single feature type to reduce feature numbers or require extensive feature engineering, potentially failing to capture intricate relationships between various features. Moreover, these methods usually assume that features are independent, which is not true for complex malware behavior. Despite their success, the reliance on handcrafted features and inability to fully leverage contextual information limits their effectiveness against sophisticated malware. To address these constraints, we introduce BERT-Cuckoo15, a malware detection model that leverages Bidirectional Encoder Representations from Transformers (BERT), to analyze relationships between diverse features derived from the dynamic analysis of samples in the Cuckoo sandbox. The model processes and encodes these features into chunks, allowing for the aggregation of contextual information across different system activities. Our evaluation, conducted on a comprehensive and balanced dataset of 36,770 samples across nine malware types, demonstrates the efficacy of our approach. BERT-Cuckoo15 achieves an accuracy of 97.61%, showcasing its ability to capture complex feature interdependencies and improve malware detection accuracy.
dc.format.extent10
dc.identifier.doihttps://doi.org/10.24251/HICSS.2025.047
dc.identifier.isbn978-0-9981331-8-8
dc.identifier.otherb2f2034b-3161-431e-baad-397fff1930ea
dc.identifier.urihttps://hdl.handle.net/10125/108883
dc.relation.ispartofProceedings of the 58th Hawaii International Conference on System Sciences
dc.rightsAttribution-NonCommercial-NoDerivatives 4.0 International
dc.rights.urihttps://creativecommons.org/licenses/by-nc-nd/4.0/
dc.subjectCybersecurity in the Age of Artificial Intelligence, AI for Cybersecurity, and Cybersecurity for AI
dc.subjectmalware detection; bert; natural language processing; transformers; feature generation; malicious behavior analysis; dynamic analysis
dc.titleBERT-Cuckoo15: A Comprehensive Framework for Malware Detection Using 15 Dynamic Feature Types
dc.typeConference Paper
dc.type.dcmiText
prism.startingpage388

Files

Original bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
0040.pdf
Size:
1.16 MB
Format:
Adobe Portable Document Format