NUST Institutional Repository

LayerLock: Multi-Layer Machine Learning based File-less Malware Detector

Show simple item record Sher, Sameeta 2024-09-18T07:56:35Z 2024-09-18T07:56:35Z 2024-09-18
dc.identifier.other 00000362075
dc.description Supervised by Associate Prof Dr. Muhammad Faisal Amjad en_US
dc.description.abstract File-less malware, a rapidly emerging threat, is a great challenge for malware detection systems because most of these detection systems use the pre-identified signatures to classify the malware. File-less malware does not generate executable files containing malicious code, thereby not generating any signature similar to file-based malware; hence, they cannot be detected and removed. File-less malware utilizes the pre-existing benign utilities of a system for execution, including PowerShell, Windows Management Instrumentation (WMI) and JavaScript. With the rapid advancements in malware landscape, researchers have shifted to developing innovative detection systems, incorporating machine learning in malware detection to benefit from its exceptional behavior towards pattern recognition and classification. This research aims to propose a solution that not only detects file less malware exploiting PowerShell, but also classify sophisticated file-less malware API sequences using machine learning. This research proposes a two-layer solution that offers two types of analysis including basic and advanced. The first layer monitors the processes and detects malicious processes chains, while second layer perform API analysis using ensemble classifiers. The proposed solution shows remarkable performance against file-less malware. en_US
dc.language.iso en en_US
dc.publisher MCS en_US
dc.title LayerLock: Multi-Layer Machine Learning based File-less Malware Detector en_US
dc.type Thesis en_US

Files in this item

This item appears in the following Collection(s)

Show simple item record

Search DSpace

Advanced Search


My Account