Bài viết

An Efficient Framework for Multi-Class Malware Classification in Cloud Environments

Từ khóaPhân loại phần mềm độc hạilấy mẫu ngẫu nhiênlọc phương sai thấp và chuẩn hoáphát hiện phần mềm độc hại trên nền tảng đám mây

Tóm tắt

Phân loại phần mềm độc hại trên môi
trường đám mây vẫn là một thách thức quan trọng
do tính phức tạp và khối lượng ngày càng tăng của
các mối đe dọa mạng. Bài báo này đề xuất CMC
(Phân loại phần mềm độc hại trên đám mây), một
khuôn khổ mới giúp tăng cường hiệu quả phân loại
phần mềm độc hại đa lớp thông qua việc tích hợp
lựa chọn tính năng, giảm chiều và các kỹ thuật xử lý
dữ liệu mất cân bằng. Khuôn khổ CMC nhằm mục
đích cải thiện độ chính xác của phân loại và hiệu quả
tính toán bằng cách tối ưu hóa biểu diễn tính năng
và giải quyết tình trạng mất cân bằng lớp, đây là
những vấn đề phổ biến trong các tập dữ liệu phần
mềm độc hại trong thế giới thực. Để đánh giá hiệu quả của khuôn khổ đề xuất, chúng tôi áp dụng CMC
cho hai tập dữ liệu chuẩn công khai: CMD_2024 và
CIC-MalMem-2022. Kết quả thử nghiệm chứng
minh rằng CMC vượt trội hơn các phương pháp
hiện có về độ chính xác phân loại, điểm F1 và hiệu
quả tính toán, chứng minh tiềm năng triển khai
trong thế giới thực của nó trong các giải pháp bảo
mật dựa trên đám mây. Những phát hiện này làm
nổi bật tầm quan trọng của việc xử lý dữ liệu thông
minh và tối ưu hóa tính năng trong việc tăng cường
phân loại phần mềm độc hại trên nền tảng đám mây.

Lượt tải theo tháng

0224406/2507/2508/2509/2510/2511/2512/2501/2602/2603/2604/2605/26

Di chuột vào cột để xem số lượt tải.

Cách trích dẫn

Phạm Sỹ Nguyên, Phạm Ngọc Vân, Hoàng Việt Long, Phạm Duy Trung (2025). An Efficient Framework for Multi-Class Malware Classification in Cloud Environments. Tạp chí Khoa học và Công nghệ trong lĩnh vực An toàn thông tin, 1(24), 40-52. https://doi.org/10.54654/isj.v1i24.1092

Tài liệu tham khảo

  1. 1.. T. Panker, A. Cohen, T. Landman, C. Bery, and N. Nissim, “Mincloud: Trusted and transferable minhash-based framework for unknown malware detection for linux cloud environments,” Journal of Information Security and Applications, vol. 87, p.
  2. 2., 2024.
  3. 3.. P. Maniriho, A. N. Mahmood, and M. J. M. Chowdhury, “A systematic literature review on windows malware detection: Techniques, research issues, and future directions,” Journal of Systems and Software, vol. 209, p. 111921, 2024.
  4. 4.. P. Mishra, T. Jain, P. Aggarwal, G. Paul, B. B. Gupta, R. W. Attar, and A. Gaurav, “Cloudintellmal: An advanced cloud based intelligent malware detection framework to analyze android applications,” Computers and Electrical Engineering, vol. 119, p. 109483, 2024.
  5. 5.. O. Aslan, M. Ozkan Okay, and D. Gupta, “A review of cloud-based malware detection system: Opportunities, advances and challenges,” 03 2021.
  6. 6.. Aslan, M. Ozkan-Okay, and D. Gupta, “Intelligent behavior-based malware detection system on cloud computing environment,” IEEE Access, vol. 9, pp. 83 252–83 271, 2021.
  7. 7.. G. Kale, G. E. Bostancı, and F. V. C¸ elebi, “Evolutionary feature selection for machine learning based malware classification,” Engineering Science and Technology, an International Journal, vol. 56, p. 101762, 2024.
  8. 8.. T. Carrier, P. Victor, A. Tekeoglu, and A. Habibi Lashkari, “Detecting obfuscated malware using memory feature engineering,” 01 2022, pp. 177–188.
  9. 9.. P. S. Nguyen, T. N. Huy, T. A. Tuan, P. D. Trung, and H. V. Long, “Hybrid feature extraction and integrated deep learning for cloud-based malware detection,” Computers & Security, vol. 150, p. 104233, 2025.
  10. 10.. S. Matharaarachchi, M. Domaratzki, and S. Muthukumarana, “Enhancing smote for imbalanced data with abnormal minority instances,” Machine Learning with Applications, vol. 18, p. 100597, 2024.
  11. 11.. H. D. Misalkar and P. Harshavardhanan, “Tdbamla: Temporal and dynamic behavior analysis in android malware using lstm and attention mechanisms,” Computer Standards & Interfaces, vol. 92, p. 103920, 2025.
  12. 12.. C. Li, Z. Cheng, H. Zhu, L. Wang, Q. Lv, Y. Wang, N. Li, and D. Sun, “Dmalnet: Dynamic malware analysis based on api feature engineering and graph learning,” Computers Security, vol. 122, p. 102872, 2022.
  13. 13.. F. H. da Costa, I. Medeiros, T. Menezes, J. V. da Silva, I. L. da Silva, R. Bonifácio, K. Narasimhan, and M. Ribeiro, “Exploring the use of static and dynamic analysis to improve the performance of the mining sandbox approach for android malware identification,” Journal of Systems and Software, vol. 183, p. 111092, 2022.
  14. 14.. H. juan Zhu, Y. Li, L. min Wang, and V. S. Sheng, “A multi-model ensemble learning framework for imbalanced android malware detection,” Expert Systems with Applications, vol. 234, p. 120952, 2023.
  15. 15.. A. Bensaoud and J. Kalita, “Cnn-lstm and transfer learning models for malware classification based on opcodes and api calls,” Knowledge-Based Systems, vol. 290, p. 111543, 2024.
  16. 16.. R. Chaganti, V. Ravi, and T. D. Pham, “Deep learning based cross architecture internet of things malware
  17. 17.detection and classification,” Computers Security, vol. 120, p. 102779, 2022.
  18. 18.. Prachi., N. Dabas, and P. Sharma, “Malanalyser: An effective and efficient windows malware detection method based on api call sequences,” Expert Systems with Applications, vol. 230, p. 120756, 2023.
  19. 19.. S. Kumar and K. Panda, “Sdif-cnn: Stacking deep image features using fine-tuned convolution neural network models for real-world malware detection and classification,” Applied Soft Computing, vol. 146, p. 110676, 2023.
  20. 20.. S. Yang, Y. Yang, D. Zhao, L. Xu, X. Li, F. Yu, and J. Hu, “Dynamic malware detection based on supervised contrastive learning,” Computers and Electrical Engineering, vol. 123, p. 110108, 2025.
  21. 21.. D. Zhang, Y. Song, Q. Xiang, and Y. Wang, “Imcmkcnn: A lightweight convolutional neural network with multi-scale kernels for image-based malware classification,” Alexandria Engineering Journal, vol. 111, pp. 203–220, 2025.
  22. 22.. B. B. Gupta, A. Gaurav, V. Arya, S. Bansal, R. W. Attar, A. Alhomoud, and K. Psannis, “Earthworm optimization algorithm based cascade lstm-gru model for android malware detection,” Cyber Security and Applications, vol. 3, p. 100083, 2025.
  23. 23.. M. Alotaibi, G. Aldehim, M. Maashi, M. M. Asiri, F. A. Alrslani, S. R. Alotaibi, A. Yafoz, and R. Alsini, “Chaos game optimization with stacked lstm sequence to sequence autoencoder for malware detection in iot cloud environment,” Alexandria Engineering Journal, vol. 112, pp. 688–700, 2025.
  24. 24.. N. Minh, N. V. Hung, and N. Shone, “Using deep graph learning to improve dynamic analysis-based malware detection in pe files,” Journal of Computer Virology and Hacking Techniques, vol. 20, pp. 1–20, 10 2023.
  25. 25.. P. V. Dinh, N. Shone, P. H. Dung, Q. Shi, N. V. Hung, and T. N. Ngoc, “Behaviour-aware malware classification: Dynamic feature selection,” in 2019 11th International Conference on Knowledge and Systems Engineering (KSE), 2019, pp. 1–5.
  26. 26.. A. C¸ ayır, U. Unal, and H. Da ¨ g, “Random capsnet forest ˘ model for imbalanced malware type classification task,” Computers Security, vol. 102, p. 102133, 2021.
  27. 27.. F. Demirkıran, A. C¸ ayır, U. Unal, and H. Da ¨ g, “An ensemble of pre-trained transformer models
  28. 28.for imbalanced multiclass malware classification,”Computers Security, vol. 121, p. 102846, 2022.
  29. 29.. L. Xue and T. Zhu, “Hybrid resampling and weighted majority voting for multi-class anomaly detection on imbalanced malware and network traffic data,” Engineering Applications of Artificial Intelligence, vol. 128, p. 107568, 2024.
  30. 30.. M. A. Latif, Z. Mushtaq, S. Rahman, S. Arif, S. Mursal, M. Irfan, and H. Aziz, “Oversamplingenhanced feature fusion based hybrid vit-1dcnn model for ransomware cyber attack detection,” Computer Modeling in Engineering Sciences, vol. 142, pp. 1667–1695, 01 2025.
  31. 31.. N. Anđelic, S. Baressi ´ Segota, and V. Mrzljak, “Application of symbolic classifiers and multiensemble threshold techniques for android malware detection,” Big Data and Cognitive Computing, vol. 9, pp. 1–49, 01 2025.
  32. 32.. M. A. R. Putra, T. Ahmad, D. P. Hostiadi, and R. M. Ijtihadie, “Ensemble network graph-based classification for botnet detection using adaptive weighting and feature extraction,” IEEE Access, vol. 13, pp. 31 183–31 204, 2025.
  33. 33.. K. S. Roy, T. Ahmed, P. B. Udas, M. E. Karim, and S. Majumdar, “Malhystack: A hybrid stacked ensemble learning framework with feature engineering schemes for obfuscated malware analysis,” Intelligent Systems with Applications, vol. 20, p. 200283, 2023.

Bài viết liên quan