A robust ensemble learning framework for binary and multiclass malware classification over diverse datasets
| dc.contributor.advisor | Hossain, Muhammad Iqbal | |
| dc.contributor.author | Arafath, Yeasin | |
| dc.contributor.author | Hossain, Apon | |
| dc.contributor.author | Nawreen, Nazihah Islam | |
| dc.contributor.author | Talukder, Tousiqul Islam | |
| dc.contributor.author | Aziz, Raisa Tahiatul | |
| dc.date.accessioned | 2025-09-15T04:43:19Z | |
| dc.date.available | 2025-09-15T04:43:19Z | |
| dc.date.issued | 2025-06 | |
| dc.description | Cataloged from PDF version of thesis. | |
| dc.description | Includes bibliographical references (pages 62-65). | |
| dc.description | This thesis is submitted in partial fulfillment of the requirements for the degree of Bachelor of Science in Computer Science, 2025. | |
| dc.description.abstract | Cybercrime has surged due to the widespread use of the Internet, posing a significant threat to global digital security, with obfuscated malware presenting a particular challenge through its sophisticated code-hiding techniques. This study addresses the classification of obfuscated malware using the CIC-MalMem-2022 dataset, comprising 29,298 memory dump samples across benign instances and multiple malware families (e.g., Spyware, Ransomware, Trojan Horse), alongside three additional datasets for testing our model. Our primary objective is to create a model that enhances the accuracy of multi-class classification, focusing on malware families, while also evaluating binary and malware category classifications. To mitigate class imbalance, we employ the Random UnderSampler technique, paired with feature selection using feature importance to identify discriminative memory-based features. The highest accuracy achieved was 99.99% for binary classification. Besides,for multiclass classification, we obtained approximately 96% and 94% (balanced dataset) for 4-class classification using RandomForest-LightGBM, and 99% and 99.99% (balanced dataset) for 16-class classification using AdaBoost-LightGBM on the primary dataset. We evaluated a range of machine learning (ML) models, including AdaBoost, Decision Tree, Random Forest, and hybrid ensembles with confidence-based refinement, among which AdaBoost-LightGBM and RandomForest-LightGBM are our proposed models. | |
| dc.identifier.other | ID 20201052 | |
| dc.identifier.other | ID 20301355 | |
| dc.identifier.other | ID 24141096 | |
| dc.identifier.other | ID 21301679 | |
| dc.identifier.other | ID 20301426 | |
| dc.identifier.other | https://dspace.bracu.ac.bd/server/api/core/items/f5558dec-55b9-4576-8111-3cb1e458bb15 | |
| dc.identifier.uri | http://hdl.handle.net/10361/26728 | |
| dc.language.iso | en | |
| dc.publisher | BRAC University | |
| dc.source | BRAC University Institutional Repository | |
| dc.subject | Cyber crime | |
| dc.subject | Obfuscated malware | |
| dc.subject | Spyware | |
| dc.subject | Polymorphic malware | |
| dc.subject | Machine learning | |
| dc.subject | Hybrid models | |
| dc.subject | Ensemble learning framework | |
| dc.title | A robust ensemble learning framework for binary and multiclass malware classification over diverse datasets | |
| dc.type | Thesis |
Files
Original bundle
1 - 1 of 1
- Name:
- 20201052, 20301355, 24141096, 21301679, 20301426_CSE.pdf
- Size:
- 466.88 KB
- Format:
- Adobe Portable Document Format
