Detailed Information

Cited 1 time in webofscience Cited 2 time in scopus
Metadata Downloads

TMaD: Three-tier malware detection using multi-view feature for secure convergence ICT environments

Authors
Jeon, JueunJeong, ByeonghuiBaek, SeungyeonJeong, Young-Sik
Issue Date
Feb-2025
Publisher
John Wiley & Sons Ltd
Keywords
cloud-fog-edge collaborative; convergence ICT; deep learning; malware detection; multi-view feature; signature-based malware detection
Citation
Expert Systems, v.42, no.2
Indexed
SCIE
SCOPUS
Journal Title
Expert Systems
Volume
42
Number
2
URI
https://scholarworks.dongguk.edu/handle/sw.dongguk/22811
DOI
10.1111/exsy.13684
ISSN
0266-4720
1468-0394
Abstract
As digital transformation accelerates, data generated in a convergence information and communication technology (ICT) environment must be secured. This data includes confidential information such as personal and financial information, so attackers spread malware in convergence ICT environments to steal this information. To protect convergence ICT environments from diverse cyber threats, deep learning models have been utilized for malware detection. However, accurately detecting rapidly generated variants and obfuscated malware is challenging. This study proposes a three-tier malware detection (TMaD) scheme that utilizes a cloud-fog-edge collaborative architecture to analyse multi-view features of executable files and detect malware. TMaD performs signature-based malware detection at the edge device tier, then sends executables detected as unknown or benign to the fog tier. The fog tier conducts static analysis on non-obfuscated executables and those transferred from the previous tier to detect variant malware. Subsequently, TMaD sends executables detected as benign in the fog tier to the cloud tier, where dynamic analysis is performed on obfuscated executables and those detected as benign to identify obfuscated malware. An evaluation of TMaD's detection performance resulted in an accuracy of 94.78%, a recall of 0.9794, a precision of 0.9535, and an f1-score of 0.9663. This performance demonstrates that TMaD, by analysing executables across several tiers and minimizing false negatives, exhibits superior detection performance compared to existing malware detection models.
Files in This Item
There are no files associated with this item.
Appears in
Collections
College of Police and Criminal Justice > Department of Police Administration > 1. Journal Articles

qrcode

Items in ScholarWorks are protected by copyright, with all rights reserved, unless otherwise indicated.

Related Researcher

Researcher Jeong, Young Sik photo

Jeong, Young Sik
College of Advanced Convergence Engineering (Department of Computer Science and Artificial Intelligence)
Read more

Altmetrics

Total Views & Downloads

BROWSE