Please use this identifier to cite or link to this item: http://hdl.handle.net/1893/37730
Appears in Collections:Computing Science and Mathematics eTheses
Title: Understanding Malware using Ontology-based knowledge graph and deep learning techniques
Author(s): Roy Chowdhury, Ipshita
Supervisor(s): Bhowmik, Deepayan
Keywords: Malware
Ontology
Deep Learning
Continual Learning
Domain Adaptation
Knowledge graph
Malware Image
Malware Behaviour
EWC
CNN
RNN
ResNets
MobileNetV2
Issue Date: 27-Mar-2025
Publisher: University of Stirling
Abstract: Due to rapid growth and advancement of Big Data and Internet of Things (IoT), industries and organizations are being the main targets of cyber criminals. As IoT enables the linking of all types of `smart' devices industrial appliances, personal information or sensitive data are being constantly attacked by novel malware variants. Therefore, in recent years cyber security has become a major concern due to the emergence of new advanced malware mutants which are causing harm to the users for financial gain to personal information loss. Due to transportation and sharing of huge amount of data, internet-enabled devices and social media platforms are becoming more vulnerable to new generation malware attacks. Because of the limitations of traditional Machine Learning based approaches, it's very difficult to deal with the new malware generations with complex behaviour and varying code structures. Different categories of malware families represents complex, dynamic behaviours and characteristics which can cause a novel and targeted attack in a cyber-system. Existence of large volume of malware types with frequent new additions hinders the cyber resilience effort. This motivation leads to develop a new ontology driven framework that can capture recent malware behaviours and construct novel malware detection and classification framework for new generation malware. This research built an ontology-based knowledge graph to capture metamorphic malware behaviour in the form of API call sequences, and it constructed a dynamic model for implementing an API-based knowledge graph from the domain ontology. The ontological structure are used as the domain knowledge to develop several deep learning algorithms have been incorporated for the prediction of new generation malware classes. In this research a number of deep learning techniques were developed for malware analysis by incorporating CNNs, ResNet-50, GANs, achieving higher accuracies than state-of-the-art models. CNNs and other deep learning architectures were implemented as standalone models and by integrating with other models as well. To address the limitations of static deep learning models, this work includes continual learning approaches to avoid catastrophic forgetting while promoting adaptability in dynamic threat environments. It further addresses two new approaches bringing ontology to Deep Learning: Domain Adaptation, transferring knowledge from one source to one target domain with results pooled in the subsequent stage and then Building Knowledge Graphs using Deep Learning-based Image Classification and Ontology Integration to better support semantic representation through structured integration of the output of classifications into structured knowledge. The overall research work has been carried out to built a meaningful domain specific ontological framework, a wide range of Deep Learning-based neural architectures have been implemented on publicly available benchmark datasets. Employment of various advanced deep learning techniques to improve accuracy and address key challenges such as catastrophic forgetting. Integration of deep learning and ontology with Domain Adaptation and construction of three deep learning based malware knowledge graphs for enhancing interpretability and advancing AI-driven malware analysis in cybersecurity.
Type: Thesis or Dissertation
URI: http://hdl.handle.net/1893/37730

Files in This Item:
File Description SizeFormat 
Ipshita Roy Chowdhury 2636546 Amended Thesis.pdf36.66 MBAdobe PDFView/Open



This item is protected by original copyright



Items in the Repository are protected by copyright, with all rights reserved, unless otherwise indicated.

The metadata of the records in the Repository are available under the CC0 public domain dedication: No Rights Reserved https://creativecommons.org/publicdomain/zero/1.0/

If you believe that any material held in STORRE infringes copyright, please contact library@stir.ac.uk providing details and we will remove the Work from public display in STORRE and investigate your claim.