Malware Triage Approach using a Task Memory based on Meta-Transfer Learning Framework
Jinting Zhu, Julian Jang-Jaccard, Ian Welch, Harith Al-Sahaf, and Seyit Camtepe

TL;DR
This paper introduces a novel malware triage method using a meta-learning framework with task memory, enabling rapid classification and prioritization of malware, including zero-day threats, to improve incident response efficiency.
Contribution
It proposes a task memory-based meta-learning approach with a Siamese neural network for fast malware classification and prioritization, addressing zero-day malware detection and reducing computational costs.
Findings
Outperforms existing classification techniques in accuracy.
Effectively identifies risky and unknown malware, including zero-day attacks.
Reduces computational costs by leveraging external task memory.
Abstract
To enhance the efficiency of incident response triage operations, it is not cost-effective to defend all systems equally in a complex cyber environment. Instead, prioritizing the defense of critical functionality and the most vulnerable systems is desirable. Threat intelligence is crucial for guiding Security Operations Center (SOC) analysts' focus toward specific system activity and provides the primary contextual foundation for interpreting security alerts. This paper explores novel approaches for improving incident response triage operations, including dealing with attacks and zero-day malware. This solution for rapid prioritization of different malware have been raised to formulate fast response plans to minimize socioeconomic damage from the massive growth of malware attacks in recent years, it can also be extended to other incident response. We propose a malware triage approach…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsNetwork Security and Intrusion Detection · Advanced Malware Detection Techniques · Anomaly Detection Techniques and Applications
