The rapid evolution of malware variants and the manual bottlenecks in reverse engineering demand automated, scalable, and resilient detection mechanisms. This dissertation investigates the application of machine learning and semantic feature extraction to mitigate human-in-the-loop dependency and address the degradation of classification models due to concept drift. The research is structured around three core contributions. First, it introduces SAUCY SPICE and its scalable evolution, Saucy Express, an unsupervised framework for automated, generalized signature generation and real-time kernel-mode blocking, enabling signature generation in a viable timeframe for rapid response. Second, it proposes the Bifocal Agent, a dual-granularity anomaly detection system that identifies malicious code regions at both the function and basic-block levels. By employing a novel 'Tails' aggregation strategy and a consensus mechanism that establishes a targeted triage "Gray Zone," the framework significantly reduces false-positive rates (from 45% to 16% compared to baselines) and streamlines the security analyst's workload. Third, the study evaluates the robustness of representation learning models (including Asm2Vec, Trex, and jTrans) against concept drift and structural modifications such as compiler optimizations. The findings reveal that current approaches fail to effectively capture code semantics, resulting in representations (embeddings) that are strongly biased toward structural artifacts. In a practical experiment, it is shown how the lack of true functional semantics limits the application of code embedding techniques for malware classification. Ultimately, this thesis provides actionable frameworks to accelerate malware characterization and exposes critical gaps in contemporary code embedding, pointing toward the necessity of domain-specific, semantic-driven approaches in cybersecurity defense

TECHNIQUES FOR MALWARE DETECTION AND ANALYSIS: A MACHINE LEARNING APPROACH(2026 Jul 13).

TECHNIQUES FOR MALWARE DETECTION AND ANALYSIS: A MACHINE LEARNING APPROACH

OLIVEIRA DA ROCHA, RAFAEL
2026-07-13

Abstract

The rapid evolution of malware variants and the manual bottlenecks in reverse engineering demand automated, scalable, and resilient detection mechanisms. This dissertation investigates the application of machine learning and semantic feature extraction to mitigate human-in-the-loop dependency and address the degradation of classification models due to concept drift. The research is structured around three core contributions. First, it introduces SAUCY SPICE and its scalable evolution, Saucy Express, an unsupervised framework for automated, generalized signature generation and real-time kernel-mode blocking, enabling signature generation in a viable timeframe for rapid response. Second, it proposes the Bifocal Agent, a dual-granularity anomaly detection system that identifies malicious code regions at both the function and basic-block levels. By employing a novel 'Tails' aggregation strategy and a consensus mechanism that establishes a targeted triage "Gray Zone," the framework significantly reduces false-positive rates (from 45% to 16% compared to baselines) and streamlines the security analyst's workload. Third, the study evaluates the robustness of representation learning models (including Asm2Vec, Trex, and jTrans) against concept drift and structural modifications such as compiler optimizations. The findings reveal that current approaches fail to effectively capture code semantics, resulting in representations (embeddings) that are strongly biased toward structural artifacts. In a practical experiment, it is shown how the lack of true functional semantics limits the application of code embedding techniques for malware classification. Ultimately, this thesis provides actionable frameworks to accelerate malware characterization and exposes critical gaps in contemporary code embedding, pointing toward the necessity of domain-specific, semantic-driven approaches in cybersecurity defense
13-lug-2026
38
INFORMATICA
DRAGO, Idilio
ALVES PEREIRA JÚNIOR, LOURENÇO
File in questo prodotto:
File Dimensione Formato  
Thesis-OLIVEIRA DA ROCHA - Rafael.pdf

Accesso aperto

Descrizione: Tesi
Dimensione 3.58 MB
Formato Adobe PDF
3.58 MB Adobe PDF Visualizza/Apri

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/2318/2152211
Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus ND
  • ???jsp.display-item.citation.isi??? ND
social impact