Next Article in Journal
Efficient Removal of Representative Chemical Agents by Rapid and Sufficient Adsorption via Magnetic Graphene Oxide Composites
Previous Article in Journal
Special Issue on “Research on Circadian Rhythms in Health and Disease”
Previous Article in Special Issue
An Efficient NIDPS with Improved Salp Swarm Feature Optimization Method
 
 
Font Type:
Arial Georgia Verdana
Font Size:
Aa Aa Aa
Line Spacing:
Column Width:
Background:
Article

Machine Learning and Deep Learning Based Model for the Detection of Rootkits Using Memory Analysis

School of Electrical Engineering and Computer Science, National University of Sciences and Technology, Islamabad 44000, Pakistan
*
Authors to whom correspondence should be addressed.
These authors contributed equally to this work.
Appl. Sci. 2023, 13(19), 10730; https://doi.org/10.3390/app131910730
Submission received: 20 July 2023 / Revised: 29 August 2023 / Accepted: 4 September 2023 / Published: 27 September 2023
(This article belongs to the Special Issue Recent Advances in Cybersecurity and Computer Networks)

Abstract

Rootkits are malicious programs designed to conceal their activities on compromised systems, making them challenging to detect using conventional methods. As the threat landscape continually evolves, rootkits pose a serious threat by stealthily concealing malicious activities, making their early detection crucial to prevent data breaches and system compromise. A promising strategy for monitoring system activities involves analyzing volatile memory. This study proposes a rootkit detection model that combines memory analysis with Machine Learning (ML) and Deep Learning (DL) techniques. The model aims to identify suspicious patterns and behaviors associated with rootkits by analyzing the contents of a system’s volatile memory. To train the model, a diverse dataset of known rootkit samples is employed, and ML and deep learning algorithms are utilized. Through extensive experimentation and evaluation using SVM, RF, DT, k-NN, and LSTM algorithms, it is determined that SVM achieves the highest accuracy rate of 96.2%, whereas Execution Time (ET) shows that k-NN depicts the best performance, and LSTM (a DL model) shows the worst performance among the tested algorithms. This research contributes to the development of advanced defense mechanisms and enhances system security against the constantly evolving threat of rootkit attacks.
Keywords: memory analysis; rootkits; deep learning; machine learning; execution time memory analysis; rootkits; deep learning; machine learning; execution time

Share and Cite

MDPI and ACS Style

Noor, B.; Qadir, S. Machine Learning and Deep Learning Based Model for the Detection of Rootkits Using Memory Analysis. Appl. Sci. 2023, 13, 10730. https://doi.org/10.3390/app131910730

AMA Style

Noor B, Qadir S. Machine Learning and Deep Learning Based Model for the Detection of Rootkits Using Memory Analysis. Applied Sciences. 2023; 13(19):10730. https://doi.org/10.3390/app131910730

Chicago/Turabian Style

Noor, Basirah, and Sana Qadir. 2023. "Machine Learning and Deep Learning Based Model for the Detection of Rootkits Using Memory Analysis" Applied Sciences 13, no. 19: 10730. https://doi.org/10.3390/app131910730

APA Style

Noor, B., & Qadir, S. (2023). Machine Learning and Deep Learning Based Model for the Detection of Rootkits Using Memory Analysis. Applied Sciences, 13(19), 10730. https://doi.org/10.3390/app131910730

Note that from the first issue of 2016, this journal uses article numbers instead of page numbers. See further details here.

Article Metrics

Back to TopTop