{"id":{"repo_id":"uwtsd","oai_identifier":"oai:repository.uwtsd.ac.uk:4289"},"canonical_url":"https://search.dev.ndltd.org/etd/uwtsd/oai:repository.uwtsd.ac.uk:4289","repository":{"repo_id":"uwtsd","name":"University of Wales Trinity Saint David","base_url":"https://repository.uwtsd.ac.uk/cgi/oai2"},"display":{"title":"A Static, Dynamic and Memory Analysis Process for Outputting Fileless Malware Prevention Software Requirement","abstract":"The number of cyber-attacks involving fileless malware has increased in recent years. It can blend in with usual system activity, leave no traces on disk and evade signature-based detection making it difficult to detect with end point detection and response systems and anti-virus software. Many studies focus on the analysis or detection of fileless malware, yet few studies focus specifically on how fileless malware could be prevented with software. Therefore, the primary objective of this study is to bridge this gap by outputting the requirements for such software. To achieve this literature relevant to fileless malwares operation, the analysis of fileless malware and existing technical mitigations was critically analysed. A fileless malware analysis environment was designed and implemented. 30 fileless malware samples were analysed using static, dynamic and memory analysis and the results were compared to the analysis of a benign sample. The key findings of the analysis were evaluated focusing specifically on the behaviours exhibited by the fileless malware samples not exhibited by the benign sample. The hypothesis that a 3-stage analysis process consisting of static, dynamic and memory analysis can output the information needed to devise the requirements for fileless malware prevention software is tested. The study aimed to discover 3 or more behaviours in 90% of the samples that could be translated into a software requirement to prove the hypothesis. The evaluation of analysis results shows that 97% of the malware samples do exhibit 3 or more behaviours that are translatable into a software requirement with an average of 5 behaviours per sample. The findings of the study show that the proposed 3-stage analysis process is an effective method for gathering requirements for fileless malware prevention software and what was discovered about fileless malware can inform researchers and cybersecurity professionals about the various approaches that could be employed to combat this allusive threat.","abstract_html":"The number of cyber-attacks involving fileless malware has increased in recent years. It can blend in with usual system activity, leave no traces on disk and evade signature-based detection making it difficult to detect with end point detection and response systems and anti-virus software. Many studies focus on the analysis or detection of fileless malware, yet few studies focus specifically on how fileless malware could be prevented with software. Therefore, the primary objective of this study is to bridge this gap by outputting the requirements for such software. To achieve this literature relevant to fileless malwares operation, the analysis of fileless malware and existing technical mitigations was critically analysed. A fileless malware analysis environment was designed and implemented. 30 fileless malware samples were analysed using static, dynamic and memory analysis and the results were compared to the analysis of a benign sample. The key findings of the analysis were evaluated focusing specifically on the behaviours exhibited by the fileless malware samples not exhibited by the benign sample. The hypothesis that a 3-stage analysis process consisting of static, dynamic and memory analysis can output the information needed to devise the requirements for fileless malware prevention software is tested. The study aimed to discover 3 or more behaviours in 90% of the samples that could be translated into a software requirement to prove the hypothesis. The evaluation of analysis results shows that 97% of the malware samples do exhibit 3 or more behaviours that are translatable into a software requirement with an average of 5 behaviours per sample. The findings of the study show that the proposed 3-stage analysis process is an effective method for gathering requirements for fileless malware prevention software and what was discovered about fileless malware can inform researchers and cybersecurity professionals about the various approaches that could be employed to combat this allusive threat.","abstract_has_math":false,"creators":["Smyth, Peter William"],"institution":"University of Wales Trinity Saint David","degree_name":"msc","degree_level":"masters","degree_discipline":null,"degree_department":null,"school":null,"contributors":[],"advisors":[],"committee_chairs":[],"committee_members":[],"year":2026,"date_issued":"2026-02","date_published":"2026-02","updated_at":"2026-07-24T05:53:11Z","subjects":["QA76 Meddalwedd Cyfrifiadurol"],"languages":[],"rights":[],"rights_urls":[],"identifier_entries":[{"key":"dc:identifier.grantnumber","label":"Dc Identifier Grantnumber","values":["UWTSD"],"render_values":[{"text":"UWTSD","href":null,"code":true}]}]},"links":{"outbound_url":"https://doi.org/10.82227/repository.uwtsd.ac.uk.00004289","outbound_label":"DOI","outbound_source":"dc:identifier.doi"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor.sponsor","label":"Sponsor","values":["University of Wales Trinity Saint David"]},{"key":"dc:creator","label":"Author","values":["Smyth, Peter William"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date","label":"Dc Date","values":["2026-02-19"]},{"key":"dc:date.issued","label":"Date","values":["2026-02"]},{"key":"dc:publisher.commercial","label":"Dc Publisher Commercial","values":["University of Wales Trinity Saint David"]},{"key":"dc:publisher.department","label":"Dc Publisher Department","values":["Traethodau Meistr","Wales Institute for Science and Art: Computing"]},{"key":"dc:publisher.institution","label":"Dc Publisher Institution","values":["University of Wales Trinity Saint David"]},{"key":"dc:relation.isreferencedby","label":"Dc Relation Isreferencedby","values":["https://repository.uwtsd.ac.uk/id/eprint/4289/"]},{"key":"dc:type","label":"Dc Type","values":["Gosodiad"]},{"key":"dc:type.qualificationlevel","label":"Dc Type Qualificationlevel","values":["masters"]},{"key":"dc:type.qualificationname","label":"Dc Type Qualificationname","values":["msc"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["QA76 Meddalwedd Cyfrifiadurol"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier.doi","label":"DOI","values":["10.82227/repository.uwtsd.ac.uk.00004289"]},{"key":"dc:identifier.grantnumber","label":"Dc Identifier Grantnumber","values":["UWTSD"]},{"key":"dc:identifier.uri","label":"Identifier URI","values":["https://repository.uwtsd.ac.uk/id/eprint/4289/1/Smyth_PW_MSc_Thesis.pdf"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description.abstract","label":"Abstract","values":["The number of cyber-attacks involving fileless malware has increased in recent years. It can blend in with usual system activity, leave no traces on disk and evade signature-based detection making it difficult to detect with end point detection and response systems and anti-virus software. Many studies focus on the analysis or detection of fileless malware, yet few studies focus specifically on how fileless malware could be prevented with software. Therefore, the primary objective of this study is to bridge this gap by outputting the requirements for such software. To achieve this literature relevant to fileless malwares operation, the analysis of fileless malware and existing technical mitigations was critically analysed. A fileless malware analysis environment was designed and implemented. 30 fileless malware samples were analysed using static, dynamic and memory analysis and the results were compared to the analysis of a benign sample. The key findings of the analysis were evaluated focusing specifically on the behaviours exhibited by the fileless malware samples not exhibited by the benign sample. The hypothesis that a 3-stage analysis process consisting of static, dynamic and memory analysis can output the information needed to devise the requirements for fileless malware prevention software is tested. The study aimed to discover 3 or more behaviours in 90% of the samples that could be translated into a software requirement to prove the hypothesis. The evaluation of analysis results shows that 97% of the malware samples do exhibit 3 or more behaviours that are translatable into a software requirement with an average of 5 behaviours per sample. The findings of the study show that the proposed 3-stage analysis process is an effective method for gathering requirements for fileless malware prevention software and what was discovered about fileless malware can inform researchers and cybersecurity professionals about the various approaches that could be employed to combat this allusive threat."]},{"key":"dc:format","label":"Dc Format","values":["text"]},{"key":"dc:title","label":"Title","values":["A Static, Dynamic and Memory Analysis Process for Outputting Fileless Malware Prevention Software Requirement"]}]}],"canonical_facts":{"dc:contributor.sponsor":["University of Wales Trinity Saint David"],"dc:creator":["Smyth, Peter William"],"dc:date":["2026-02-19"],"dc:date.issued":["2026-02"],"dc:description.abstract":["The number of cyber-attacks involving fileless malware has increased in recent years. It can blend in with usual system activity, leave no traces on disk and evade signature-based detection making it difficult to detect with end point detection and response systems and anti-virus software. Many studies focus on the analysis or detection of fileless malware, yet few studies focus specifically on how fileless malware could be prevented with software. Therefore, the primary objective of this study is to bridge this gap by outputting the requirements for such software. To achieve this literature relevant to fileless malwares operation, the analysis of fileless malware and existing technical mitigations was critically analysed. A fileless malware analysis environment was designed and implemented. 30 fileless malware samples were analysed using static, dynamic and memory analysis and the results were compared to the analysis of a benign sample. The key findings of the analysis were evaluated focusing specifically on the behaviours exhibited by the fileless malware samples not exhibited by the benign sample. The hypothesis that a 3-stage analysis process consisting of static, dynamic and memory analysis can output the information needed to devise the requirements for fileless malware prevention software is tested. The study aimed to discover 3 or more behaviours in 90% of the samples that could be translated into a software requirement to prove the hypothesis. The evaluation of analysis results shows that 97% of the malware samples do exhibit 3 or more behaviours that are translatable into a software requirement with an average of 5 behaviours per sample. The findings of the study show that the proposed 3-stage analysis process is an effective method for gathering requirements for fileless malware prevention software and what was discovered about fileless malware can inform researchers and cybersecurity professionals about the various approaches that could be employed to combat this allusive threat."],"dc:format":["text"],"dc:identifier.doi":["10.82227/repository.uwtsd.ac.uk.00004289"],"dc:identifier.grantnumber":["UWTSD"],"dc:identifier.uri":["https://repository.uwtsd.ac.uk/id/eprint/4289/1/Smyth_PW_MSc_Thesis.pdf"],"dc:publisher.commercial":["University of Wales Trinity Saint David"],"dc:publisher.department":["Traethodau Meistr","Wales Institute for Science and Art: Computing"],"dc:publisher.institution":["University of Wales Trinity Saint David"],"dc:relation.isreferencedby":["https://repository.uwtsd.ac.uk/id/eprint/4289/"],"dc:subject":["QA76 Meddalwedd Cyfrifiadurol"],"dc:title":["A Static, Dynamic and Memory Analysis Process for Outputting Fileless Malware Prevention Software Requirement"],"dc:type":["Gosodiad"],"dc:type.qualificationlevel":["masters"],"dc:type.qualificationname":["msc"]},"updated_at":"2026-07-24T05:53:11Z"}