Back to results

University of Wales Trinity Saint David

A Static, Dynamic and Memory Analysis Process for Outputting Fileless Malware Prevention Software Requirement

Abstract

dc:description.abstract

The number of cyber-attacks involving fileless malware has increased in recent years. It can blend in with usual system activity, leave no traces on disk and evade signature-based detection making it difficult to detect with end point detection and response systems and anti-virus software. Many studies focus on the analysis or detection of fileless malware, yet few studies focus specifically on how fileless malware could be prevented with software. Therefore, the primary objective of this study is to bridge this gap by outputting the requirements for such software. To achieve this literature relevant to fileless malwares operation, the analysis of fileless malware and existing technical mitigations was critically analysed. A fileless malware analysis environment was designed and implemented. 30 fileless malware samples were analysed using static, dynamic and memory analysis and the results were compared to the analysis of a benign sample. The key findings of the analysis were evaluated focusing specifically on the behaviours exhibited by the fileless malware samples not exhibited by the benign sample. The hypothesis that a 3-stage analysis process consisting of static, dynamic and memory analysis can output the information needed to devise the requirements for fileless malware prevention software is tested. The study aimed to discover 3 or more behaviours in 90% of the samples that could be translated into a software requirement to prove the hypothesis. The evaluation of analysis results shows that 97% of the malware samples do exhibit 3 or more behaviours that are translatable into a software requirement with an average of 5 behaviours per sample. The findings of the study show that the proposed 3-stage analysis process is an effective method for gathering requirements for fileless malware prevention software and what was discovered about fileless malware can inform researchers and cybersecurity professionals about the various approaches that could be employed to combat this allusive threat.

Degree

thesis:*
Name dc:type.qualificationname
msc
Level dc:type.qualificationlevel
masters
Grantor dc:publisher.institution
University of Wales Trinity Saint David
Year dc:date.issued
2026

Author and committee

dc:creator, dc:contributor.*
Author dc:creator
  • Smyth, Peter William

Subjects

dc:subject × 1

Identifiers

dc:identifier.*
Dc Identifier Grantnumber
UWTSD
OAI identifier oai:identifier
oai:repository.uwtsd.ac.uk:4289

Chain of custody

source
Harvested from
University of Wales Trinity Saint David
Base URL
repository.uwtsd.ac.uk/cgi/oai2
Last updated
2026-07-24
Source record
OAI-PMH GetRecord
citation

Smyth, Peter William. A Static, Dynamic and Memory Analysis Process for Outputting Fileless Malware Prevention Software Requirement. masters thesis, University of Wales Trinity Saint David, 2026. https://doi.org/10.82227/repository.uwtsd.ac.uk.00004289