Early Malware Detection through Temporal Analysis of System Behaviors

Authors

  • Juan Li Shanghai Jiao Tong University Master of Science in Communication and Information Systems Author
  • Wenkun Ren Information Technology and Management, Illinois Institute of Technology, Chicago, IL Author
  • Xiaolan Wu Northeastern University Computer Science Author

Keywords:

Temporal Analysis, Malware Detection, System Behavior Monitoring, Time-Series Classification

Abstract

Early detection of malware is crucial for minimizing potential damage to computer systems and sensitive data. This paper investigates the application of temporal analysis techniques for identifying malicious software during early stages of infection. We focus on analyzing time-series patterns in system behaviors, including process activities, file operations, and network connections. The study examines how temporal features can reveal malicious intent before significant harm occurs. We employ sliding window analysis and sequence pattern mining to extract relevant temporal characteristics from system event logs. The research compares the effectiveness of different time window sizes and evaluates both rule-based and machine learning approaches for temporal anomaly detection. We also investigate behavioral differences across various malware lifecycle stages, from initial execution through propagation. Our experimental analysis demonstrates that temporal features can provide valuable signals for early detection. This work offers security practitioners a complementary detection method that focuses on behavioral sequences rather than static signatures, potentially improving detection rates for previously unknown malware variants while maintaining acceptable performance overhead in production environments. 

Author Biography

  • Xiaolan Wu, Northeastern University Computer Science

     

     

Downloads

Published

2023-01-05

How to Cite

Early Malware Detection through Temporal Analysis of System Behaviors. (2023). Journal of Global Engineering Review, 1(1), 1-11. https://gereview.com/index.php/jger/article/view/3