Organizations: Artificial Intelligence Research (AIR) Center · School of Electrical Engineering and Computer Science, College of Engineering & Mines University of North Dakota, Grand Forks, ND 58201, USA
By 2030, Internet of Things (IoT) devices are projected to reach 40 billion, with fast-paced technological advancements in fields such as industry, healthcare, agriculture, automobiles, and building/home automation systems. This expansion has created a large attack surface for cybercrime, as the majority of these devices open the door for cybercriminals to exploit vulnerabilities, as they lack adequate built-in security. Cybercriminals launch malware attacks to compromise systems or steal sensitive data, and once a system is compromised, a ransom is typically demanded for its release. Current cybersecurity measures in place are being outpaced by the rapid growth of the IoT, which is accompanied by a subsequent growth in malware variants being created per day. Recognizing this pitfall, this research examines and proposes a novel approach to malware detection and classification to safeguard devices from further attacks and make IoT systems more robust and secure. The framework proposed utilizes a Structured State Space Sequence (S4) model, which discretizes sequences of malware samples in a sequence and captures long-range dependencies, essentially identifying the "cause" and "effect" hidden within malware execution flow. This study presents two novel contributions: the first empirical application of the S4 model for malware analysis, and a comprehensive comparison of its performance against other deep learning architectures, laying the stepping stone for future research in this new paradigm.
Figures & tables
Fig. 1 : Overall System Workflow
Fig. 2 : Overview of the proposed state space based malware classification architecture, showing the sequence construction stage, stacked state space blocks with residual connections, and dual feed-forward classification networks. The discrete-time dynamics within a single state space block are shown in the lower-left panel.
Component
Setting
Number of input features ( D )
71
Sequence length ( L )
32
Model dimension ( dmodel )
128
State dimension ( dstate )
64
Number of state space blocks
3
State space layers per block
1
TABLE I : Configuration of the proposed state space based model
Fig. 3 : Training and validation loss, binary detection accuracy, and malware family classification accuracy over 50 training epochs.
Parameter
Values
Model dimension ( dmodel )
{128, 256}
State dimension ( dstate )
{32, 64}
Number of state space blocks
{2, 3}
Learning rate
{1e-4, 5e-4}
Family loss weight
{0.5, 0.7}
Dropout rate
{0.1, 0.2}
TABLE II : Hyperparameter search space used for grid search tuning
Metric
Formula
Accuracy
TP+TN+FP+FNTP+TN
Precision
TP+FPTP
Recall
TP+FNTP
F1-score
Precision+Recall2⋅Precision⋅Recall
Macro-average
C1∑i=1Cmi
Weighted-average
∑i=1Cwimi
TABLE III : Evaluation metrics used for malware classification
Fig. 4 : Binary malware detection performance across evaluated models in terms of accuracy, precision, recall, and F1-score.
Fig. 5 : Per-class F1-scores for the selected ransomware families across different model architectures.
Fig. 6 : Per-class precision for the selected ransomware families across different model architectures.
Fig. 7 : Per-class recall for the selected ransomware families across different model architectures.
Fig. 8 : Summary of macro-averaged and weighted performance metrics for malware family classification across evaluated models.