Submitted:
04 December 2024
Posted:
04 December 2024
You are already at the latest version
Abstract
Malware has emerged as a significant threat to end-users, businesses, and governments, resulting in financial losses of billions of dollars. Cybercriminals have found malware to be a lucrative business because of its evolving capabilities and ability to target diverse platforms such as PCs, mobile devices, IoT, and cloud platforms. While previous studies have explored single platform-based malware detection, no existing research has comprehensively reviewed malware detection across diverse platforms using machine learning (ML) tactics. With the rise of malware on PC/laptop devices, it is now targeting mobile devices and IoT systems, posing a significant threat to cloud environments. Therefore, a platform-based understanding of malware detection and defense mechanisms is essential for countering this evolving threat. To fill this gap and motivate further research, we present an extensive review of malware detection using ML techniques with respect to PCs, mobile devices, IoT, and cloud platforms. This paper begins with an overview of malware, including its definition, prominent types, impacts, analysis, and features. It presents a comprehensive review of machine learning-based malware detection from recent literature, including journal articles, conference proceedings, and online resources published since 2017. This survey also offers insights into current challenges and outlines future directions for developing adaptable cross-platform malware detection techniques. This survey is crucial for understanding the evolving threat landscape and developing robust detection strategies.
Keywords:
1. Introduction
- To the best of our knowledge, this is the first comprehensive review of malware detection in PCs, mobile devices, IoT systems, and cloud environments using machine-learning techniques.
- This study details the various types of features (e.g., static, dynamic, memory, and hybrid) used to train the ML models. It also discusses the malware landscape across platforms and identifies both platform-specific challenges and cross-platform issues that affect the development of effective ML-based malware detection techniques.
- This study examines existing malware detection techniques using various ML and DL models and provides the overall research trends observed for each platform.
- This study highlights gaps in the existing research and proposes future directions, such as developing adaptable, scalable, and efficient ML algorithms for multiple platforms and promoting unified cross-platform malware detection approaches.
2. Comparison with Previous Related Surveys
3. Malware Fundamentals
3.1. What is Malware
3.2. Leading Malware Threats in the Current Cyber Landscape
3.4. Malware Analysis
- Static analysis
- Dynamic analysis
- Memory analysis and
- Hybrid analysis
3.5. Features Used in ML-Based Malware Detection
4. Malware Landscape Across Platforms
4.1. PCs
4.1.1. Windows
4.1.2. Linux
4.1.3. macOS
4.2. Mobile Devices
4.2.1. Android
4.2.2. iOS
4.3. IoT Platform
4.4. Cloud Environments
5. Machine Learning Algorithms for Malware Detection
Overall Research Trends on Machine Learning Algorithms for Malware Detection Across Different Platforms
6. Application of Machine Learning on Malware Detection
6.1. PC (Personal Computers) Malware Detection
6.1.1. Malware Detection in Windows platform
| Reference | Data source | Feature category | Features | ML algorithms | Result (accuracy) | Limitations |
|---|---|---|---|---|---|---|
| Static feature-based malware detection | ||||||
| [63] | Malimg | Static | Opcode sequences | Deep RNN | 96% | It requires significant computational resources |
| [73] | Microsoft BIG 2015 | Static | Opcodes, images, byte sequence, etc | DNN, LSTM, and CNN. | 98.35% | It is useless against zero-day malware. |
| [102] | BIG 2015, Malimg, MaleVis and Malicia dataset | Static | 2D images | DenseNet | 98.23% | It has high false negatives and highly imbalanced datasets |
| [74] | Microsoft BIG 2015 | Static | Image-based opcode features | CNN | 99.12% | Outdated dataset |
| [103] | Malimg dataset, Microsoft BIG 2015 | Static | Grayscale images from PE files | VGG16, VGG19, ResNet50, and inceptionV3 | 98.92% | Cannot detect advanced-packed malware |
| [106] | Malimg | Static | Static signatures | ATT-DNNs | 98.09% | Cannot detect obfuscated malware |
| [75] | Malware API-class | Static | Executable file to static images | CNN | 98.00% | _ |
| [76] | VirusShare, Hybrid-Analysis | Static | Executable file to static images | Xception Convolutional Neural Network (CNN) | 98.20% | _ |
| [107] | Microsoft BIG 2015 | Static | Malware binary files into static images | DNN | 97.80% | _ |
| Dynamic feature-based malware detection | ||||||
| [92] | VirusShare | Dynamic | Sequences of API calls | Bi-LSTM | 97.31% | Limited to execute samples in a Windows 7 environment. |
| [108] | Custom datasets | Dynamic | Sequences of API calls | Markov chain representation | 99.7% | - |
| [109] | VirusTotal | Dynamic | API calls | LSTM | 95% | Limited to execute samples in a Windows 7 environment. |
| [93] | VirusTotal | Dynamic | API call sequences | LSTM and GRU | 96.8% | Highly imbalanced dataset |
| [64] | CA Tech- neologises VET Zoo |
Dynamic | Run time behaviour | MRed, ReliefF, SVM | 99.499% | High computational complexity |
| [94] | Audit log events | Dynamic | Process names, action types, and accessed file | LSTM | 91.05% | High false positives and lack of scalability |
| [77] | Multiclass dataset (Ember Dataset, private dataset) | Dynamic | loaded DLLs, registry changes, API call sequences, file changes, and | CNN-LSTM | 96.8% | Susceptible to adversarial attacks |
| Hybrid feature-based Malware Detection Techniques | ||||||
| [78] | VirusTotal | Hybrid (Static and dynamic) |
Combination of static and dynamic features (PE section, PE import, PE API, and PE images) | CNN | 97% | Failed to validate the robustness against adversarial attacks |
| [71] | The Korea Internet & Security Agency (KISA) | Hybrid | Size of file and Header, Counts of file sections. Entropy, File system changes API call, DLL loaded info, network activities, etc. |
RF, MLP | 85.1% | Extensive time is needed for feature extraction |
| [104] | VirusShare | Hybrid | Image-based static and dynamic features | VGG16 | 94.70% | - |
| [110] | VirusShare | Hybrid | Function Length Frequency Representation, Registry activities, API calls, and file operation features |
SVM | 97.10% | Small dataset |
| [79] | VirusTotal | Hybrid | Opcodes and system calls | CNN, LSTM, and an attention-based LSTM | 99% | Lack of diverse features. |
| Memory-feature-based malware detection techniques. | ||||||
| [80] | Dumpware10 | Memory | Memory images of running processes | CNN | 98% | Malware processing cost is high under limited resource capabilities |
| [81] | Dumpware10, BIG2015 dataset | Memory | Memory images of running processes | GAN and CNN | 99.86% for BIG2015 dataset | Only one type of data, like bytes, is used. Need to make the dataset more diverse. |
| [82] | CIC-MalMem-2022 https://www.unb.ca/cic/datasets/malmem-2022.html |
Memory | Memory images of running processes | CNN and MLP | 99.8% | Training time complexity and vulnerability to adversarial attacks |
| [68] | CIC-MalMem-2022 https://www.unb.ca/cic/datasets/malmem-2022.html |
Memory | Multi-memory features | RF, DT, LR, MLP and CNN | 99.89% | - |
Static feature-Based Malware Detection Techniques
Dynamic Feature-Based Malware-Detection Techniques
Hybrid-Feature-Based Malware Detection Techniques
Memory-Feature-Based Malware Detection Techniques
Summary of Key Trends and Insights on Malware Detection in Windows Platforms
6.1.2. Malware Detection in Linux OS
Summary of Key Trends on Malware Detection in Linux Platform
6.1.3. Malware Detection in macOS
Summary of Key Trends on Malware Detection in macOS Platform
6.2. Malware Detection in Mobile Platform
6.2.1. Android Malware Detection
Static Feature-Based Malware Detection Techniques
Dynamic Feature-Based Malware Detection Techniques
Hybrid-Feature-Based Malware Detection Techniques
Memory-Feature-Based Malware Detection Techniques
6.2.2. Malware Detection in iOS
6.3. Malware Detection in IoT Platform
Summary of Research Trends on Malware Detection in IoT Platform
6.4. Malware Detection in Cloud Platform
Summary of research Trends on Malware Detection in IoT Platform
7. Challenges Associated with Platform-Specific and Cross-Platform
- The use of outdated Windows versions, which no longer receive official support, exposes the systems to unpatched vulnerabilities.
- The variety of third-party applications on Windows expands the attack surface, thereby increasing the risk of exploitation.
- The rise of fileless malware, which primarily lives in memory, presents challenges for traditional detection and mitigation methods.
- Inconsistent user behavior and poor adherence to security best practices increases vulnerability.
- Linux systems support diverse computer architectures, requiring analysts to create specific malware analysis codes for each architecture, leading to high costs and operational complexity owing to extensive code management.
- The analysis environment may lack the necessary loader for the ELF file format, thereby preventing sample execution.
- Constructing refined datasets is difficult because of the varied devices, vendors, and architectures of Linux systems.
- Moreover, complexity demands expert manual analysis.
- As macOS gains market share, it increasingly targets malware, which requires continuous advancements in detection techniques.
- The limited tools available for malware analysis of macOS hinder large-scale studies.
- Owing to the historically low prevalence of malware, MacOS users may be less vigilant about security risks.
- Android’s dependency on multiple manufacturers slows OS updates, leaving many outdated devices and exposed to security risks.
- Third-party Android apps elevate malware risks, thereby threatening device security and user privacy.
- Unlike iOS, Android allows users to control permissions, potentially enabling malicious apps to misuse the granted access.
- The variety of Android devices and OS versions complicate uniform patching and security protocols.
- Android’s open-source framework enables adversaries to examine their code, facilitating reverse engineering and exploitation creation.
- iOS’s auto-erase feature of iOS enhances security but may cause unintended data loss following unsuccessful login attempts.
- Despite advanced Face ID, earlier iOS versions were vulnerable to photos or masks, compromising security.
- iOS apps use obfuscation to prevent reverse engineering; however, skilled attackers can bypass these defenses to access sensitive data.
- In summary, Android’s flexibility through open-source and diverse devices creates scalability but risks security, whereas iOS enhances security with strict policies, thus limiting flexibility. Future research should focus on balancing security, usability, and standardization.
- Most IoT devices use the Android operating system, which is open-sourced and, unlike iOS, is more vulnerable to exposure.
- IoT devices possess considerably less computing power than x86-architecture PCs, making them highly vulnerable to malware due to their limited resources.
- In machine and deep learning, larger datasets facilitate faster model learning and improvement. However, there is a significant shortage of valid datasets of IoT malware.
- The interconnected nature of the cloud infrastructure increases the impact of malware.
- A shared responsibility model for cloud security can obscure responsible security tasks. This can lead to organizations having limited visibility and control, thus hindering threat detection and response.
- Attackers can leverage the automation and scalability features of the cloud to quickly launch large-scale attacks.
- Data heterogeneity: Variations in file formats, system call sequences, and behavioral patterns across platforms make it challenging to create generalized models.
- Lack of unified datasets: The absence of a standardized, diverse, and large-scale dataset that incorporates samples from Windows, macOS, Linux, Android, IoT, and cloud environments.
- Inconsistent feature representations: Differences in how features like static metadata, dynamic behavior, and memory traces are extracted and represented across platforms.
- Transferability of models: ML models trained on one platform (e.g., Windows) may not generalize well to others (e.g., Linux or IoT) because of differences in malware characteristics.
- Performance scalability: Ensuring scalability and efficiency of detection techniques when applied to cloud and IoT systems with resource limitations.
- These challenges emphasize the need for a multi-platform approach to malware detection that considers platform-specific constraints while addressing overarching cross-platform issues.
8. Limitations in the Existing Literature and Future Research Directions
Lack of Unified Cross-Platform Detection Frameworks
Insufficient Model Adaptability to Emerging Malware Variants
High Computational Demands of ML Models in Resource-Constrained Environments
Limited Transparency and Interpretability of ML-Driven Detection Systems
Lack of Comprehensive, Labelled Datasets for Multi-Platform Malware Detection
Vulnerability to Adversarial Attacks
Limited Research on Hybrid Detection Approaches Combining Static, Dynamic, and Memory Analysis
9. Conclusion
References
- M. H. Nguyen, D. Le Nguyen, X. M. Nguyen, and T. T. Quan, “Auto-detection of sophisticated malware using lazy-binding control flow graph and deep learning,” Comput. Secur., vol. 76, pp. 128–155, 2018. [CrossRef]
- Companies, “2024 Cisco Cybersecurity Readiness Index,” 2024. [Online]. Available: https://newsroom.cisco.com/c/dam/r/newsroom/en/us/interactive/cybersecurity-readiness-index/documents/Cisco_Cybersecurity_Readiness_Index_FINAL.pdf.
- N. J. Palatty, “Top Malware Attack Statistics, astra 2024. https://www.getastra.com/blog/security-audit/malware-statistics/ (accessed October 15, 2024). 15 October.
- Forbes, “Why Ransomware Should Be On Every Cybersecurity Team’s Radar,” 2022. https://www.forbes.com/councils/forbestechcouncil/2022/04/12/why-ransomware-should-be-on-every-cybersecurity-teams-radar/#:~:text=According to Cybersecurity Ventures%2C victims, business up and running again. (accessed October 15, 2024). 15 October.
- B. Toulas, “Linux malware sees 35% growth during 2021,” 2022. https://www.bleepingcomputer.com/news/security/linux-malware-sees-35-percent-growth-during-2021/ (accessed October 19, 2024).
- V. GANDH, “2023 ThreatLabz Report Indicates 400% Growth in IoT Malware Attacks,” 2023. https://www.zscaler.com/blogs/security-research/2023-threatlabz-report-indicates-400-growth-iot-malware-attacks (accessed October 15, 2024).
- J. Singh and J. Singh, “A survey on machine learning-based malware detection in executable files,” J. Syst. Archit., vol. 112, no. March 2020, p. 101861, 2021. [CrossRef]
- S. Sibi Chakkaravarthy, D. Sangeetha, and V. Vaidehi, “A Survey on malware analysis and mitigation techniques,” Comput. Sci. Rev., vol. 32, pp. 1–23, 2019. [CrossRef]
- U.-H. Tayyab, F. B. Khan and M. H. Durad, A. Khan, and Y. S. Lee, “A Survey of the Recent Trends in Deep Learning Based Malware Detection,” J. Cybersecurity Priv., vol. 2, no. 4, pp. 800–829, 2022. [CrossRef]
- Q. Wu, X. Zhu, and B. Liu, “A Survey of Android Malware Static Detection Technology Based on Machine Learning,” Mob. Inf. Syst., vol. 2021, 2021. [CrossRef]
- D. Gibert, C. Mateu, and J. Planes, “The rise of machine learning for detection and classification of malware: Research developments, trends and challenges,” J. Netw. Comput. Appl., vol. 153, p. 102526, March 2020. [CrossRef]
- Y. Liu, C. Tantithamthavorn, L.; Li, Y. Liu, “Deep Learning for Android Malware Defenses: A Systematic Literature Review,” ACM Comput. Surv., vol. 55, no. 8, pp. 1–36, 2023. [CrossRef]
- Z. Wang, Q. Liu, and Y. Chi, “Review of Android malware detection based on deep learning,” IEEE Access, vol. 8, pp. 181102–181126, 2020. [CrossRef]
- P. Victor, A. Habibi, L. Rongxing, L. Tinshu, S. Pulei, and X. Shahrear, IoT malware: An attribute - based taxonomy , detection mechanisms and challenges. Springer US, 2023.
- C. Alex, G. Creado, W. Almobaideen, O. A. Alghanam, and M. Saadeh, “A Comprehensive Survey for IoT Security Datasets Taxonomy , Classification and Machine Learning Mechanisms,” Comput. Secur., p. 103283, 2023. [CrossRef]
- Gaurav, B. B., Gupta, and P. K. Panigrahi, “A comprehensive survey on machine learning approaches for malware detection in IoT-based enterprise information system,” Enterp. Inf. Syst., vol. 17, no. 3, 2023. [CrossRef]
- P. Maniriho, A. N. Mahmood, and M. J. M. Chowdhury, “A Survey of Recent Advances in Deep Learning Models for Detecting Malware in Desktop and Mobile Platforms,” ACM Comput. Surv., vol. 56, no. 6, 2024. [CrossRef]
- S. Abijah Roseline and S. Geetha, “A comprehensive survey of tools and techniques mitigating computer and mobile malware attacks,” Comput. Electr. Eng., vol. 92, no. October 2020, p. 107143, 2021. [CrossRef]
- M. M. Belal and D. M. Sundaram, “Comprehensive review on intelligent security defences in cloud: Taxonomy, security issues, ML/DL techniques, challenges and future trends,” J. King Saud Univ. - Comput. Inf. Sci., vol. 34, no. 10, pp. 9102–9131, 2022. [CrossRef]
- Aslan, M. Ozkan-Okay, and D. Gupta, “Intelligent Behavior-Based Malware Detection System on Cloud Computing Environment,” IEEE Access, vol. 9, pp. 83252–83271, 2021. [CrossRef]
- M. Gopinath and S. C. Sethuraman, “A comprehensive survey on deep learning-based malware detection techniques,” Comput. Sci. Rev., vol. 47, p. 100529, 2023. [CrossRef]
- Sanda, M. and Pavlidis, N. Polatidis, “A deep learning approach for host-based cryptojacking malware detection,” Evol. Syst., vol. 15, no. 1, pp. 41–56, 2024. [CrossRef]
- J. Ferdous et al., “Malware−Resistant Data Protection in Hyper−connected Networks: A Survey,” https://arxiv.org/pdf/2307.13164, 2023, [Online]. Available: https://arxiv.org/abs/2307.13164.
- Mitchell, “Current Malware Trends: 5 Most Common Types of Malware in 2024,” lumifi, 2024. https://www.lumificyber.com/blog/current-malware-trends-5-most-common-types-of-malware-in-2024/ (accessed October 23, 2024).
- J. Ferdous, R. Islam, A. Mahboubi, and M. Z. Islam, “A Review of State-of-the-Art Malware Attack Trends and Defense Mechanisms,” IEEE Access, vol. 11, no. October, pp. 121118–121141, 2023. [CrossRef]
- M. BURGESS, “Conti’s Attack Against Costa Rica Sparks a New Ransomware Era,” WIRED, 2022. https://www.wired.com/story/costa-rica-ransomware-conti/ (accessed October 23, 2024). 23 October.
- B. Toulas, “REvil ransomware member extradited to the U.S. to stand trial for Kaseya attack,” BLEEPING COMPUTER, 2022. https://www.bleepingcomputer.com/news/security/revil-ransomware-member-extradited-to-us-to-stand-trial-for-kaseya-attack/ (accessed October 23, 2024).
- M. S. and N. Perlroth, “DarkSide, Blamed for gas pipeline attack, Says It Is Shutting Down. New York Times 2021. https://www.nytimes.com/2021/05/14/business/darkside-pipeline-hack.html (accessed October 23, 2024).
- Gatlan, “Accenture confirms data breach after August ransomware attack,” BLEEPING COMPUTER, 2021. https://www.bleepingcomputer.com/news/security/accenture-confirms-data-breach-after-august-ransomware-attack/ (accessed October 23, 2024).
- E. Kost, “What is an Advanced Persistent Threat (APT)?” UpGuard, 2024. https://www.upguard.com/blog/what-is-an-advanced-persistent-threat (accessed October 23, 2024).
- Sharma, B. B. Gupta, A. K. Singh and V. K. Saraswat, “Orchestration of APT malware evasive manoeuvers employed for eluding anti-virus and sandbox defense,” Comput. Secur., vol. 115, p. 102627, 2022. [CrossRef]
- Masood, R. Samar, and M. A. Z. Raja, “Design of a mathematical model for the Stuxnet virus in a network of critical control infrastructure,” Comput. Secur., vol. 87, p. 101565, 2019. [CrossRef]
- Jain, “Decoding cryptojacking: What is it and how can you protect yourself,” Crypto.news, 2024. https://crypto.news/what-is-cryptojacking-how-does-it-work/ (accessed October 24, 2024).
- FORTINET, “Cryptojacking (learns how cryptojacking works and gains access to and abuses computer resources).,” FORTINET, 2024. https://www.fortinet.com/resources/cyberglossary/cryptojacking#:~:text=Cryptojacking is also referred to, overall health of your network. (Accessed October 24, 2024).
- R. Stevens, “Crypto mining botnet found on Defense Department web server,” 2020. https://decrypt.co/18738/crypto-mining-botnet-found-on-defense-department-web-server (accessed October 24, 2024).
- R. Stevens, “Man fined $7,000 for using Russian supercomputer to mine Bitcoin,” Decrypt, 2019. https://decrypt.co/9751/man-fined-for-using-russian-supercomputer-to-mine-crypto (accessed October 24, 2024).
- Wolf, “13 Types of Malware Attacks — and How You Can Defend Against Them,” 2024. https://arcticwolf.com/resources/blog/8-types-of-malware/ (accessed October 24, 2024).
- K. Baker, “The 12 Most Common Types of Malwares,” CROWDSTRIKE, 2023. https://www.crowdstrike.com/en-us/cybersecurity-101/malware/types-of-malware/ (accessed October 24, 2024).
- P. Maniriho, A. N. Mahmood, and M. J. M. Chowdhury, “A study on malicious software behaviour analysis and detection techniques: Taxonomy, current trends and challenges,” Futur. Gener. Comput. Syst., vol. 130, pp. 1–18, 2022. [CrossRef]
- J. Ferdous, R. Islam, A. Mahboubi, and M. Z. Islam, “AI-based Ransomware Detection: A Comprehensive Review,” IEEE Access, vol. 12, no. September 2024. [CrossRef]
- Kara, “Fileless malware threats: Recent advances, analysis approach through memory forensics and research challenges,” Expert Syst. Appl., vol. 214, no. April 2022, p. 119133, 2023. [CrossRef]
- R. Kumar, X. Zhang, W. Wang, R. U. Khan, J. Kumar, and A. Sharif, “A Multi-modal Malware Detection Technique for Android IoT Devices Using Various Features,” IEEE Access, vol. 7, pp. 64411–64430, 2019. [CrossRef]
- T. Panker and N. Nissim, “Leveraging malicious behavior traces from volatile memory using machine learning methods for trusted unknown malware detection in Linux cloud environments,” Knowledge-Based Syst., vol. 226, August 2021. [CrossRef]
- H. Oz, A. Aris, A. Levi, and A. S. Uluagac, “A Survey on Ransomware: Evolution, Taxonomy, and Defense Solutions,” ACM Comput. Surv., vol. 1, no. 1, 2022. [CrossRef]
- T. A. Unit, “VMware Threat Report – Exposing Malware in Linux-Based Multi-Cloud Environments,” 2022. https://blogs.vmware.com/security/2022/02/2022-vmware-threat-report-exposing-malware-in-linux-based-multi-cloud-environments.html (accessed November 04, 2024).
- R. Walsh, “Linux Malware Stats and Facts for 2024,” 2024. https://www.comparitech.com/blog/vpn-privacy/linux-malware-stats-and-facts/ (accessed November 04, 2024).
- Y. E. T. M. Meshi, “Battling macOS Malware with Cortex AI,” 2023. https://www.paloaltonetworks.com/blog/security-operations/battling-macos-malware-with-cortex-ai/ (accessed November 04, 2024).
- B. Report, “macOS Threat Landscape Report,” 2023.
- Ani Petrosyan, “Number of detected malicious installation packages on mobile devices worldwide from 4th quarter 2015 to 3rd quarter 2023,” Statista, 2024. https://www.statista.com/statistics/653680/volume-of-detected-mobile-malware-packages/ (accessed October 27, 2024).
- Sherif, “Market share of mobile operating systems worldwide from 2009 to 2024, by quarter,” Statista, 2024. https://www.statista.com/statistics/272698/global-market-share-held-by-mobile-operating-systems-since-2009/ (accessed November 01, 2024).
- H. Haidros Rahima Manzil and S. Manohar Naik, “Detection approaches for android malware: Taxonomy and review analysis,” Expert Syst. Appl., vol. 238, no. PF, p. 122255, 2024. [CrossRef]
- Saracino, D. Sgandurra, G. Dini, and F. Martinelli, “MADAM: Effective and Efficient Behavior-based Android Malware Detection and Prevention,” IEEE Trans. Dependable Secur. Comput., vol. 15, no. 1, pp. 83–97, 2018. [CrossRef]
- S. Garg and N. Baliyan, “Comparative analysis of Android and iOS from a security viewpoint,” Comput. Sci. Rev., vol. 40, p. 100372, 2021. [CrossRef]
- Y. Shen and H. Wuhan, “Enhancing data security of iOS client by encryption algorithm,” IEEE 2nd Adv. Inf. Technol. Electron. Autom. Control Conf., pp. 366–370, 2017.
- M. Lutaaya, “Rethinking app permissions on iOS,” Conf. Hum. Factors Comput. Syst. - Proc., vol. 2018-April, pp. 1–6, 2018. [CrossRef]
- J. Phungglan, “Most common viruses on iPhone,” 2023. https://macpaw.com/how-to/most-common-iphone-viruses (accessed November 03, 2024).
- R. Walsh, “iOS Malware Stats and Facts for 2024,” 2024. https://www.comparitech.com/blog/vpn-privacy/ios-malware-stats-and-facts/ (accessed November 03, 2024).
- K. O’Flaherty, “New ‘Dangerous’ iPhone Spyware Attack Warning Issued To iOS Users,” 2024. https://www.forbes.com/sites/kateoflahertyuk/2024/04/19/new-dangerous-iphone-spyware-attack-warning-issued-to-ios-users/ (accessed November 03, 2024).
- L. S. Vailshery, “Number of Internet of Things (IoT) connections worldwide from 2022 to 2023, with forecasts from 2024 to 2033,” Statista, 2024. https://www.statista.com/statistics/1183457/iot-connected-devices-worldwide/ (accessed November 05, 2024).
- C. San Jose, “Zscaler ThreatLabz Finds a 400% Increase in IoT and OT Malware Attacks Year-over-Year, Underscoring Need for Better Zero Trust Security to Protect Critical Infrastructures,” Zscaler, 2023. https://www.zscaler.com/press/zscaler-threatlabz-finds-400-increase-iot-and-ot-malware-attacks-year-over-year-underscoring (accessed November 05, 2024).
- R. M. Yadav, “Effective analysis of malware detection in cloud computing,” Comput. Secur., vol. 83, pp. 14–21, 2019. [CrossRef]
- F. Kilonzi, “Cloud Malware: Types of Attacks and How to Defend Against Them,” 2023. https://thenewstack.io/cloud-malware-types-of-attacks-and-how-to-defend-against-them/ (accessed November 25, 2024).
- S. Jeon and J. Moon, “Malware-Detection Method with a Convolutional Recurrent Neural Network Using Opcode Sequences,” Inf. Sci. (Ny)., vol. 535, pp. 1–15, 2020. [CrossRef]
- S. Huda, R. Islam, J. Abawajy, J. Yearwood, M. M. Hassan, and G. Fortino, “A hybrid-multi filter-wrapper framework to identify run-time behaviour for fast malware detection,” Futur. Gener. Comput. Syst., vol. 83, pp. 193–207, June 2018. [CrossRef]
- M. K. Alzaylaee, S. Y. Yerima, S. Sezer, “DL-Droid: Deep learning based android malware detection using real devices,” vol. 89, 2020. [CrossRef]
- N. A. Stoian, “Machine Learning for Anomaly Detection in IoT networks: Malware analysis on the IoT-23 Data set,” Univ. Twente, 2020.
- M. He, Y. Huang, X. Wang, P. Wei, and X. Wang, “A Lightweight and Efficient IoT Intrusion Detection Method Based on Feature Grouping,” IEEE Internet Things J., vol. 11, no. 2, pp. 2935–2949, 2024. [CrossRef]
- Mezina and R. Burget, “Obfuscated malware detection using dilated convolutional network,” Int. Congr. Ultra Mod. Telecommun. Control Syst. Work., vol. 2022-Octob, pp. 110–115, 2022. [CrossRef]
- J. Mitchell, N. McLaughlin, and J. Martinez-del-Rincon, “Generating sparse explanations for malicious Android opcode sequences using hierarchical LIME,” Comput. Secur., vol. 137, no. July 2023, p. 103637, 2024. [CrossRef]
- N. Potha, V. Kouliaridis, G. Kambourakis, “An extrinsic random-based ensemble approach for android malware detection,” Conn. Sci., vol. 33, no. 4, pp. 1077–1093, 2021. [CrossRef]
- S. Yoo, S. Kim, S. Kim, and B. B. Kang, “AI-HydRa: Advanced hybrid approach using random forest and deep learning for malware classification,” Inf. Sci. (Ny)., vol. 546, pp. 420–435, 2021. [CrossRef]
- “No Title.”.
- E. Snow, M. Alam, A. Glandon, and K. Iftekharuddin, “End-to-end Multimodel Deep Learning for Malware Classification,” Proc. Int. Jt. Conf. Neural Networks, 2020. [CrossRef]
- Darem, J. Abawajy, A. Makkar, A. Alhashmi, and S. Alanazi, “Visualization and deep-learning-based malware variant detection using OpCode-level features,” Futur. Gener. Comput. Syst., vol. 125, pp. 314–323, 2021. [CrossRef]
- F. O. Catak, J. Ahmed, K. Sahinbas, and Z. H. Khand, “Data Augmentation based Malware Detection Using Convolutional Neural Networks,” PeerJ Comput. Sci., vol. 7, pp. 1–26, 2021. [CrossRef]
- C. C. Moreira, D. C. Moreira, C., de S. d. Sales, “Improving ransomware detection based on portable executable header using Xception convolutional neural network,” Comput. Secur., vol. 130, p. 103265, 2023. [CrossRef]
- C. Jindal, C. Salls, H. Aghakhani, K. Long, C. Kruegel, and G. Vigna, “Neurlux: Dynamic malware analysis without feature engineering,” ACM Int. Conf. Proceeding Ser., pp. 444–455, 2019. [CrossRef]
- R. Chaganti, V. Ravi, T. D. Pham, “A multi-view feature fusion approach for effective malware classification using Deep Learning,” J. Inf. Secur. Appl., vol. 72, no. December 2022, p. 103402, 2023. 20 December. [CrossRef]
- H. Darabian et al., “Detecting Cryptomining Malware: a Deep Learning Approach for Static and Dynamic Analysis,” J. Grid Comput., vol. 18, no. 2, pp. 293–303, 2020. [CrossRef]
- M. R. Naeem et al., “A Malware Detection Scheme via Smart Memory Forensics for Windows Devices,” Mob. Inf. Syst., vol. 2022, 2022. [CrossRef]
- Tekerek and M. M. Yapici, “A novel malware classification and augmentation model based on convolutional neural network,” Comput. Secur., vol. 112, p. 102515, 2022. [CrossRef]
- H. Naeem, S. Dong, O. J. Falana, and F. Ullah, “Development of a deep stacked ensemble with process based volatile memory forensics for platform independent malware detection and classification,” Expert Syst. Appl., vol. 223, no. February, p. 119952, 202. [CrossRef]
- T. Landman and N. Nissim, “Deep-Hook: A trusted deep learning-based framework for unknown malware detection and classification in Linux cloud environments,” Neural Networks, vol. 144, pp. 648–685, 2021. [CrossRef]
- Pektaş and T. Acarman, “Learning to detect Android malware via opcode sequences,” Neurocomputing, vol. 396, pp. 599–608, 2020. [CrossRef]
- M. Aamir et al., “AMDDLmodel: Android smartphones malware detection using deep learning model,” pp. 1–16, 2024. [CrossRef]
- H. Naeem, S. Dong, O. J. Falana, and F. Ullah, “Development of a deep stacked ensemble with process based volatile memory forensics for platform independent malware detection and classification,” Expert Syst. Appl., vol. 223, no. October 2022, p. 119952, 2023. [CrossRef]
- K. L. K. Sudheera, D. M. Divakaran, R. P. Singh, and M. Gurusamy, “ADEPT: Detection and Identification of Correlated Attack Stages in IoT Networks,” IEEE Internet Things J., vol. 8, no. 8, pp. 6591–6607, 2021. [CrossRef]
- D. Vasan, M. Alazab, S. Venkatraman, J. Akram, and Z. Qin, “MTHAEL: Cross-architecture iot malware detection based on neural network advanced ensemble learning,” IEEE Trans. Comput., vol. 69, no. 11, pp. 1654–1667, 2020. [CrossRef]
- H. V. Le, Q. D. Ngo, and V. H. Le, “Iot botnet detection using system call graphs and one-class CNN classification,” Int. J. Innov. Technol. Explor. Eng., vol. 8, no. 10, pp. 937–942, 2019. [CrossRef]
- R. Shire, S. Shiaeles, K. Bendiab, B. Ghita, and N. Kolokotronis, Malware Squid: A Novel IoT Malware Traffic Analysis Framework Using Convolutional Neural Network and Binary Visualisation, vol. 11660 LNCS. Springer International Publishing, 2019.
- H. Jiang, J. Lin, and H. Kang, “FGMD: A robust detector against adversarial attacks in the IoT network,” Futur. Gener. Comput. Syst., vol. 132, pp. 194–210, 2022. [CrossRef]
- C. Li, Q. Lv, N. Li, Y. Wang, D. Sun, and Y. Qiao, “A novel deep framework for dynamic malware detection based on API sequence intrinsic features,” Comput. Secur., vol. 116, 2022. [CrossRef]
- W. R. Aditya, Girinoto, R. B. Hadiprakoso, and A. Waluyo, “Deep Learning for Malware Classification Platform using Windows API Call Sequence,” Proc. - 3rd Int. Conf. Informatics; Multimedia; Cyber; Inf. Syst. ICIMCIS 2021, pp. 25–29, 2021. [CrossRef]
- M. Ring, D. Schlör, S. Wunderlich, D. Landes, and A. Hotho, “Malware detection on windows audit logs using LSTMs,” Comput. Secur., vol. 109, p. 102389, 2021. [CrossRef]
- M. S. A Lakshmanarao, “Android Malware Detection with Deep Learning using RNN from Opcode Sequences.,” Int. J. Interact. Mob. Technol., vol. 16, 2022.
- H. Ge, Z. Wang, Y. Liu, and X. Liu, “D ROIDETEC: Android Malware Detection and Malicious Code,” pp. 1–13.
- S. K. Sasidharan and C. Thomas, “MemDroid - LSTM based Malware Detection Framework for Android Devices,” 2021 IEEE Pune Sect. Int. Conf., pp. 1–6, 2021. [CrossRef]
- E. Amer and S. El-sappagh, “Robust deep learning early alarm prediction model based on the behavioral smell for Android malware,” Comput. Secur., vol. 116, p. 102670, 2022. [CrossRef]
- Y. Wu, J. Shi, P. Wang, D. Zeng, and C. Sun, “Android malware detection,” No. January 2022, pp. 118–130, 2023. 20 January. [CrossRef]
- J. Jeon, B. Jeong, S. Baek and Y. S. Jeong, “Hybrid Malware Detection Based on Bi-LSTM and SPP-Net for Smart IoT,” IEEE Trans. Ind. Informatics, vol. 18, no. 7, pp. 4830–4837, 2022. [CrossRef]
- S. Mahdavifar, D. Alhadidi, and A. A. Ghorbani, Effective and Efficient Hybrid Android Malware Classification Using Pseudo - Label Stacked Auto - Encoder, vol. 30, no. 1. Springer US, 2022.
- J. Hemalatha, S. A. Roseline, S. Geetha, S. Kadry, and R. Damaševičius, “An efficient densenet-based deep learning model for malware detection,” Entropy, vol. 23, no. 3, pp. 1–23, 2021. [CrossRef]
- S. Kumar and B. Janet, “DTMIC: Deep transfer learning for malware image classification,” J. Inf. Secur. Appl., vol. 64, no. December 2021, p. 103063, 2022. [CrossRef]
- X. Huang, L. Ma, W. Yang, and Y. Zhong, “A Method for Windows Malware Detection Based on Deep Learning,” J. Signal Process. Syst., vol. 93, no. 2–3, pp. 265–273, 2021. [CrossRef]
- P. Xu, Y. Zhang, C. Eckert, and A. Zarras, HawkEye: Cross-Platform Malware Detection with Representation Learning on Graphs, vol. 12893 LNCS. Springer International Publishing, 2021.
- S. K. J. Rizvi, W. Aslam, M. Shahzad, S. Saleem, and M. M. Fraz, “PROUD-MAL: static analysis-based progressive framework for deep unsupervised malware classification of windows portable executable,” Complex Intell. Syst., vol. 8, no. 1, pp. 673–685, 2022. [CrossRef]
- M. Khan, D. Baig, U. S. Khan, and A. Karim, “Malware Classification Framework using Convolutional Neural Network,” 1st Annu. Int. Conf. Cyber Warf. Secur. ICCWS 2020 - Proc., 2020. [CrossRef]
- E. Amer and I. Zelinka, “A dynamic Windows malware detection and prediction method based on contextual understanding of API call sequence,” Comput. Secur., vol. 92, p. 101760, 2020. [CrossRef]
- F. O. Catak, A. F. Yazi, O. Elezaj, and J. Ahmed, “Deep learning based Sequential model for malware analysis using Windows exe API Calls,” PeerJ Comput. Sci., vol. 6, pp. 1–23, 2020. [CrossRef]
- M. M. Hasan and M. M. Rahman, “RansHunt: A support vector machines based ransomware analysis framework with integrated feature set,” 20th Int. Conf. Comput. Inf. Technol. ICCIT 2017, vol. 2018-Janua, pp. 1–7, 2018. [CrossRef]
- E. M. B. Karbab, M. Debbabi, and A. Derhab, “SwiftR: Cross-platform ransomware fingerprinting using hierarchical neural networks on hybrid features,” Expert Syst. Appl., vol. 225, no. March, p. 120017, 2023. [CrossRef]
- C. Hwang, J. Hwang, J. Kwak, and T. Lee, “Platform-independent malware analysis applicable to windows and linux environments,” Electron., vol. 9, no. 5, 2020. [CrossRef]
- T. Set and T. Set, “Mac Malware Detection via Static File Structure Analysis,” pp. 1–5.
- H. H. Pajouh, A. and Dehghantanha, R. Khayami, and K. K. R. Choo, “Intelligent OS X malware threat detection with code inspection,” J. Comput. Virol. Hacking Tech., vol. 14, no. 3, pp. 213–223, 2018. [CrossRef]
- H. Gao, S. Cheng, and W. Zhang, “GDroid: Android malware detection and classification with graph convolutional network,” Comput. Secur., vol. 106, p. 102264, 2021. [CrossRef]
- S. Wang, Z. Chen, Q. Yan, B. Yang, L. Peng, and Z. Jia, “A mobile malware detection method using behavior features in network traffic,” J. Netw. Comput. Appl., vol. 133, no. December 2018, pp. 15–25, 2019. 20 December. [CrossRef]
- Cimitile, F. Martinelli, and F. Mercaldo, “Machine learning meets ios malware: Identifying malicious applications on apple environment,” ICISSP 2017 - Proc. 3rd Int. Conf. Inf. Syst. Secur. Priv., vol. 2017-Janua, no. Icissp, pp. 487–492, 2017. [CrossRef]
- G. Zhou, M. Duan, Q. Xi, and H. Wu, “ChanDet: Detection Model for Potential Channel of iOS Applications,” J. Phys. Conf. Ser., vol. 1187, no. 4, 2019. [CrossRef]
- F. Mercaldo and A. Santone, “Deep learning for image-based mobile malware detection,” J. Comput. Virol. Hacking Tech., vol. 16, no. 2, pp. 157–171, 2020. [CrossRef]
- H. V. Le and Q. D. Ngo, “V-Sandbox for Dynamic Analysis IoT Botnet,” IEEE Access, vol. 8, pp. 145768–145786, 2020. [CrossRef]
- X. Zhou, W. Liang, W. Li, K. Yan, S. Shimizu, and K. I. K. Wang, “Hierarchical Adversarial Attacks Against Graph-Neural-Network-Based IoT Network Intrusion Detection System,” IEEE Internet Things J., vol. 9, no. 12, pp. 9310–9319, 2022. [CrossRef]
- Guerra-Manzanares, J. Medina-Galindo, H. Bahsi, and S. Nomm, “MedBIoT: Generation of an IoT Botnet Dataset in a Medium-sized IoT Network,” Int. Conf. Inf. Syst. Secur. Priv., no. Icissp 2020, pp. 207–218, 2020. [CrossRef]
- L. Xiao, Y. Li, X. Huang, and X. Du, “Cloud-based malware detection game for mobile devices with offloading,” IEEE Trans. Mob. Comput., vol. 16, no. 10, pp. 2742–2750, 2017. [CrossRef]






| Papers | Year | Main contribution | Insights into malware | ML-based malware detection in diverse platform | Challenges identified | |||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Latest prominent malware variants | Platform-based malware taxonomy | Analysis methods (Static, dynamic, memory and hybrid) | Feature details | Pcs | Mobile | IoT | Cloud | |||||
| Windows | Linux | |||||||||||
| [7] | 2021 | Survey on malware detection techniques using machine learning algorithms. | × | × | √ | × | √ | × | × | × | × | × |
| [8] | 2019 | Survey on sophisticated attack and evasion techniques used by the contemporary malwares. | × | × | ≈ | × | √ | × | × | × | × | × |
| [9] | 2022 | This survey is on the use of Deep Learning-based malware detection. | × | × | ≈ | × | √ | × | × | × | × | × |
| [10] | 2021 | Reviewed machine learning methods for Android malware detection. | × | × | √ | × | × | × | √ | × | × | × |
| [11] | 2020 | Study on traditional and state-of-the- art ML techniques for malware detection | × | × | ≈ | √ | √ | × | × | × | × | × |
| [12] | 2023 | DL approaches for malware defenses in the Android environment | × | × | √ | √ | × | × | √ | × | × | × |
| [13] | 2020 | Android malware detection using deep learning | × | × | ≈ | √ | × | × | √ | × | × | × |
| [14] | 2023 | Survey on IoT malware taxonomy and detection mechanisms. | × | ≈ | × | × | × | × | × | √ | × | √ |
| [15] | 2023 | Discussed IoT dataset use to evaluate the machine learning techniques. | × | × | ≈ | × | × | × | × | √ | × | × |
| [16] | 2023 | Review on emerging machine learning algorithms for detecting malware in IoT. | × | × | × | × | × | × | × | √ | × | × |
| [17] | 2024 | Modern deep learning technologies for identifying malware on Windows, Linux, and Android platforms. | × | × | √ | ≈ | √ | √ | √ | × | × | × |
| [18] | 2021 | Computer-based and mobile-based malware detection and, their countermeasures are presented. | × | × | ≈ | × | √ | × | √ | × | × | √ |
| [19] | 2022 | ML and DL based defenses against attacks and security issues in cloud computing is provided. | × | × | × | × | × | × | × | × | √ | √ |
| [20] | 2021 | Behavior-based malware detection system in the cloud environment | × | × | ≈ | × | × | × | × | × | × | × |
| Our survey | 2024 | Survey on malware detection in PC, mobile, IoT and cloud platform using ML techniques. | √ | √ | √ | √ | √ | √ | √ | √ | √ | √ |
| File Format | Static Features | Dynamic Features | Memory Features | |
|---|---|---|---|---|
| Windows | Executable (EXE) files |
PE headers information: Import/export address tables, section headers, entry point address, date timestamp, code section size. File metadata: Size, creation/modification dates, access permissions. Strings: IP addresses, domain names. Opcode sequences: An opcode is an instruction executed by a CPU, describing an executable file’s behavior. Hence, opcode sequences are the specific sequences of operations extracted from the binary code. |
API Calls: Sequence and types of Windows API calls (e.g., CreateProcess, WriteFile) Registry modifications: Registry key creation, deletion, or modification. File system modifications: Deletes, create, or overwrites the existing file, encrypts all or a subset of files in case of ransomware. Host logs: Events extracted from host logs. Network activity: Source and destination IP addresses, TCP ports, Domain Names System (DNS) requests, and network protocols (e.g., HTTP, HTTPS, SMTP etc.) Resource usage: Higher CPU or memory usage may indicate the presence of malware in the system. |
Windows memory dumps |
| Linux | Executable and Linkable Format (ELF): code, data, and metadata for execution. |
ELF header information: Malware developers manipulate ELF headers to evade or crash standard analysis tools [43]. Internal Libraries: Most Linux malware is statically linked to its libraries, eliminating external dependencies [43]. Shared libraries: List of dynamically loaded libraries. Sections and segments: Information on the .text (code) and .data (global variables) segments. |
System-call patterns: Frequency and type of system calls. Network behavior: Monitoring outgoing/incoming connections and socket creation. |
Sections and Segments: Memory segments (.text, .data, .bss). |
| macOS | Mach-O files: native executable format for macOS. |
Code signatures: Presence and structure of code signing. Dynamic libraries: Information on loaded libraries (DYLIBs). |
File activity: Monitor file creations, deletions, modifications, and access patterns. Inbound and outbound traffic: observe and analyze all network traffic, including DNS, HTTP requests, and other communication protocols. Service start/stop: Track each modification linked to service operation. TI Reputation services: Utilize threat intelligence feeds to detect malicious files, IP addresses, and domains. |
Sandboxing: Memory protection through entitlements. |
| Android |
APK (Android Package Kit) files: -It is a compressed archive that includes all resources needed to distribute and install applications on Android devices. |
Strings: Domain names, IP addresses, and ransom notes in case of ransomware attack Permissions analysis: The set of permissions requested by the app to the users (e.g., camera access, network communication, Bluetooth, contacts, and more). Manifest information: Details about application components (e.g., activities, services, and receivers), Intents: Allows communication between various components of an app. API calls: API calls enable inter-application communication and monitoring them can detect malicious behavior. |
Behavioural features: Network communication, SMS, data storage behavior. File system features: Similar to PCs, features extracted from a mobile device’s file system can indicate the presence of malware. User interaction: Detecting ransomware can be achieved by correlating user interactions with application runtime events [44]. System resource analysis: CPU, memory and baterry, process reports and network usage. Network traffic analysis: URLs, IPs, Network Protocols, Certificates, Non-encrypted data |
Embedded files: Presence of assets (e.g., shared libraries) impacting memory allocation. Memory dumps: A snapshot of Android’s memory that captures all data and processes in the RAM at a specific time, including system processes, application data, and temporary data from various programs |
| iOS | iOS App Store Package (IPA): specific to iOS for app distribution. |
Code signing: Verification of signatures. Sandboxing and entitlements: Permission restrictions. |
Objective-C method calls: Runtime behavior. Dynamic behavior: API usage patterns (e.g., contacts, location access). Data encryption: Encrypted data usage. |
Entitlements: Defines memory boundaries through sandboxing. |
| IoT | Various formats (e.g., BIN, HEX, Linux executables). |
Firmware version: Metadata, updates, and patches. Opcode sequences: extracting operational codes after disassembling the binary file. Control flow graph (CFG): extracting from the assembly file API calls: extracting from the binary |
Network traffic: Service type (http, smtp, ftp etc.), Device communication protocols (e.g., MQTT, CoAP), Packet size transmitted by Source IP address, etc. Device-specific behavior: Interactions with sensors, actuators, device ports. System-calls: Timestamp, return value, arguments, and name of each System-calls. CPU usage, Process usage, Ram usage and. |
System-call sequences: System-level commands specific to device memory. Memory mapped IO: Monitoring interactions with memory mapped I/O (MMIO). Memory buffer usage: Analysis of memory buffers for potential overflows. |
| Cloud | VM disk images (e.g., VMDK, QCOW2), container formats (e.g., Docker im ages). |
VM metadata: Hypervisor information (e.g., VM details). Data storage patterns: Interactions with cloud storage. Strings and n-grams |
API usage patterns: Cloud-specific API calls (AWS SDK, Google Cloud API).Container activity: Monitoring processes, network activity in containers. System calls: Extracted from the interactions between applications and the OS’s kernel during runtime. |
Virtual memory dumps: Contains memory-specific features (system calls, memory access). |
| ML techniques | Algorithms | References |
|---|---|---|
| Traditional Machine Learning Algorithms | ||
| Support Vector Machines (SVM): This method employs a hyperplane to maximize the margin between malicious and benign samples, proving effective for high-dimensional data. | SVM | [64,65,66] |
| K-Nearest Neighbors (KNN): This algorithm classifies samples based on the predominant class of their nearest neighbors, utilizing feature similarity as the primary criterion. | KNN | [52,67] |
| Logistic Regression (LR): This approach classifies malware by modelling the relationship between features and binary outcomes (malicious or benign) utilizing a sigmoid function. The sigmoid function converts input values to a range of 0 to 1, making it ideal for interpreting results as probabilities. It is used for binary classification tasks, especially in logistic regression and neural networks. | LR | [68,69,70] |
| Naïve Bayes (NB): A probabilistic approach that assumes feature independence, which is efficient for text-based malware detection. | NB | [65,66] |
| Decision Trees (DT): Decision trees are a supervised learning method that classify data by building a tree-like model. The process identifies the most critical features and splits the data into subsets based on these attributes to form nodes. It recursively classifies each node until a final decision is reached as benign or malware | DT | [68,67] |
| Ensemble Learning Algorithms | ||
| Random Forest (RF): This approach constructs multiple decision trees and aggregates their outputs through majority voting or averaging, thereby enhancing robustness and accuracy. | RF | [65,66,67,68,70,71,72] |
| Gradient Boosting (e.g., XGBoost, LightGBM): This approach sequentially constructs weak learners, specifically decision trees, to minimize errors, thereby providing high accuracy in the analysis of structured malware data. | Gradient Boosting | [70] |
| XGBoost | [67,70] | |
| AdaBoost: This approach focuses on challenging samples by modifying weights during the training process, thereby combining weak classifiers into a robust one. | AdaBoost | [66,72] |
| Bagging: The Bagging technique randomly divides the dataset into multiple subsets (bootstraps) based on in-stances, each with unique instances, and then aggregates the results from models trained on these subsets to enhance generalization | ||
| Deep learning technique | ||
| Convolutional Neural Networks (CNNs): This approach demonstrates efficacy in image-based malware detection, utilizing automated extraction of spatial features from transformed malware binaries. | CNN | [63,68,73,74,75,76,77,78,79,80,81,82,83,84,85,86,87,88,89] |
| Recurrent Neural Networks (RNNs): This method Facilitates the analysis of sequential data, including API call sequences and opcode patterns, for behavioral-based malware identification. | RNN | [63,88,90,91] |
| Long Short-Term Memory (LSTM): A variant of Recurrent Neural Network (RNN) that effectively captures long-term dependencies, particularly applicable for time-series analysis of dynamic malware features. | LSTM | [73,77,79,84,91,92,93,94,95,96,97,98,99,100] |
| Gated Recurrent Unit (GRU): It is a type of recurrent neural network (RNN) designed to process sequential data, such as time series or text. This model is more computationally efficient than LSTMs due to fewer parameters and the absence of a separate output gate. | GRU | [93] |
| Generative Adversarial Networks (GANs): This process generates synthetic malware samples for data augmentation, thereby enhancing the efficacy of detection systems with limited datasets. | GAN | [81] |
| Autoencoders: Autoencoders are unsupervised neural networks used for dimensionality reduction, feature extraction, and anomaly detection. They aim to learn a compressed representation of the input data (encoding) and then reconstruct the input (decoding) as accurately as possible. | VAEs, Sparse Autoencoders etc. | [101] |
| Transformer Models (e.g., BERT): Transformers are advanced deep learning architectures based on attention mechanisms designed to handle sequential or contextual data effectively. | BERT (Bidirectional Encoder Representations from Transformers) | |
| Transfer learning (TL): This is a deep learning approach where a model pre-trained on one task or dataset is reused and fine-tuned for a related but different task. It is particularly effective when the target dataset is small or lacks diversity. | Pre-trained CNNs like ResNet, Inception, VGG, ResNet50 etc. | [102,103,104] |
| Multilayer Perceptron (MLP): It is a type of artificial neural network (ANN) consisting of multiple layers of nodes. It is commonly used in supervised learning tasks such as classification and regression. | MLP | [52,66,68,71,82,86,105] |
| Reference | Data source | Feature category | Features | ML algorithms | Result (accuracy) |
|---|---|---|---|---|---|
| [105] | AndroZoo, VirusShare, and clean Ubuntu libraries. | Static | Assembly instructions (control flow graphs) | MLP | 96.82% |
| [112] | VirusShare | Static | Strings from binary data | DNN | 94% |
| [72] | VX heavens | Dynamic | System calls | J48, random forest, AdaBoostM1 (J48), and IBk | 98% |
| [83] | VirusShare | Memory | Memory dumps | CNN | 99.9% |
| [43] | VirusTotal and ViruShare. |
Memory | Multi-memory features | DNNs | 98.8% |
| Reference | Data source | Feature category | Features | ML algorithms | Accuracy | Limitations |
|---|---|---|---|---|---|---|
| Static feature-based Android malware detection techniques. | ||||||
| [115] | MalGenome | Static | Call graphs | GCN | 98.99% | Lack of representative of real-world scenarios. |
| [84] | Contagio Mobile | Static | Opcode sequences | CNN-LSTM | 91.42% | Unable to manage obfuscated malware |
| [69] | MalDroid-2020 dataset | Static | Opcode sequences (histograms of n-grams) | LR | 93.56% | Adversarial attack resistance and handling evolving malware are not addressed. |
| [95] | CIC-Inves2017 | Static | Opcode sequences | LSTM | 96% | Small dataset (1,500 apps) |
| [70] | Drebin, VirusShare, AndroZoo | Static | Permissions, Intents | Base models (LR, MLP, and SGD), Ensemble learning | 99.1% | - |
| [85] | Drebin dataset | Static | Opcode sequences, Permissions, API calls | CNN | 99.92% | lack of malware diversity and scalability |
| Dynamic feature-based Android malware detectiontechniques | ||||||
| [65] | McAfee | Dynamic | Actions/Events | Base models (NB, SL, SVM Linear, SVM RBF, J48, PART, RF), deep learning |
97.8% | - |
| [96] | Google Play Store https://play.google.com/store/games?pli=1 |
Dynamic | API calls | Bi-LSTM | 97.22% | High detection time |
| [116] | Drebin dataset | Dynamic | Network traffic Permissions, Intents, API calls |
C4.5 | 97.89% | Small dataset |
| [97] | MalGenome | Dynamic | System call sequences | LSTM | 99.23%. | - |
| [98] | Custom dataset | Dynamic | API and system call sequences | LSTM | 96.8% |
|
| Hybrid feature-based Android malware detectiontechniques | ||||||
| [65] | McAfee | Hybrid | Permissions, Intents, API Calls, Actions/Events | Base models (NB, SL, SVM Linear, SVM RBF, J48, PART, RF), deep learning |
99.6% detection | - |
| [52] | Contagio Mobile, http://contagiominidump.blogspot.com/ VirusShare and Genome |
Hybrid | Runtime behaviors across various levels—kernel, application, user, and package | K-NN, LDC, QDC, MLP, Parzen Classifier (PARZC) and RBF | 96% | This method is susceptible to mimicry attacks and ineffective against unknown malware. |
| [99] | VirusShare, Drebin, DroidAnalytics and CICInvesAndMal2019/2000 https://www.unb.ca/cic/datasets/invesandmal2019.html. |
Hybrid | Permissions requests, API and system call sequences, opcode sequences, and graph structures, including abstract syntax trees, control-flow, and data-flow graphs. | Bi-LSTM and GNN | 95.94% | Need more scalable static analyses |
| [101] | CICMal- Droid2020 | Hybrid | Permissions, intents, system calls, composite behaviors, and network traffic packets. | Pseudo-label stacked auto-encoder (PLSAE) | 98.28% | - |
| Memory feature-based Android malware detectiontechniques. | ||||||
| [86] | AndroZoo project https://androzoo.uni.lu/ |
Memory | Process memory dumps | Ensemble of MLP and CNN | 94.3% |
Vulnerable to adversarial attacks |
| Reference | Data source | Feature category | Features | ML algorithms | Accuracy (%) |
|---|---|---|---|---|---|
| [66] | IoT-23 dataset | Static | Network capture files include IP address, ID of the capture, protocol, etc. | RF, NB, MLP, SVM, and AdaBoost. | 99.5 |
| [87] | NSS Mirai Dataset latest relevant, balanced data sets https://www.stratosphereips.org/datasets-iot23 |
Static | Alert level (Source and Destination IP Addresses, C&C activities, Protocol) and packet level features ((IP address or port number, packet size, etc.) | CNN | 99 |
| [88] | ARM-based IoT | Static | OpCode features | RNN and CNN | 99.98 |
| [89] | Executable and Linkable Format (ELF) file templates are executed in the QEMU sandbox. | Dynamic | System call graph | CNN | 97 |
| [100] | KISA-data challenge 2019-Malware.04, provided by the Korea Internet & Security Agency | Hybrid | Opcode and API call sequences | Bi-LSTM and spatial pyramid pooling network (SPP-Net) | 92.09 |
| [90] | Network traffic is collected from external repositories. | Dynamic | 2D Image-Based Network Traffic Features | Neural network | 91.32 |
| [67] | Bot-IoT, MedBIoT, and MQTT-IoT-IDS2020 datasets | Dynamic | Packet-level metadata of the raw PCAP file | DT, RF, K-nearest neighbor (KNN), and extreme gradient boosting (XGB) | 99.5 with RF |
| [91] | MedBIoT dataset [122]. IoTID (IoT network intrusion dataset) http://dx.doi.org/10.21227/q70p-q449. |
Dynamic | PCAP files | LSTM, RNN and DT, respectively. | 98.71 |
| [121] | UNSW-SOSR2019 | Static | Network packets (source IP, destination IP, timestamp, traffic flows, etc.) | Graph neural network (GNN) | - |
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2024 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license (https://creativecommons.org/licenses/by/4.0/).