University of Wales Trinity Saint David
A Static, Dynamic and Memory Analysis Process for Outputting Fileless Malware Prevention Software Requirement
Abstract
dc:description.abstractThe number of cyber-attacks involving fileless malware has increased in recent years. It can blend in with usual system activity, leave no traces on disk and evade signature-based detection making it difficult to detect with end point detection and response systems and anti-virus software. Many studies focus on the analysis or detection of fileless malware, yet few studies focus specifically on how fileless malware could be prevented with software. Therefore, the primary objective of this study is to bridge this gap by outputting the requirements for such software. To achieve this literature relevant to fileless malwares operation, the analysis of fileless malware and existing technical mitigations was critically analysed. A fileless malware analysis environment was designed and implemented. 30 fileless malware samples were analysed using static, dynamic and memory analysis and the results were compared to the analysis of a benign sample. The key findings of the analysis were evaluated focusing specifically on the behaviours exhibited by the fileless malware samples not exhibited by the benign sample. The hypothesis that a 3-stage analysis process consisting of static, dynamic and memory analysis can output the information needed to devise the requirements for fileless malware prevention software is tested. The study aimed to discover 3 or more behaviours in 90% of the samples that could be translated into a software requirement to prove the hypothesis. The evaluation of analysis results shows that 97% of the malware samples do exhibit 3 or more behaviours that are translatable into a software requirement with an average of 5 behaviours per sample. The findings of the study show that the proposed 3-stage analysis process is an effective method for gathering requirements for fileless malware prevention software and what was discovered about fileless malware can inform researchers and cybersecurity professionals about the various approaches that could be employed to combat this allusive threat.
Degree
thesis:*- Name dc:type.qualificationname
- msc
- Level dc:type.qualificationlevel
- masters
- Grantor dc:publisher.institution
- University of Wales Trinity Saint David
- Year dc:date.issued
- 2026
Author and committee
dc:creator, dc:contributor.*- Author dc:creator
-
- Smyth, Peter William
Subjects
dc:subject × 1Identifiers
dc:identifier.*- Dc Identifier Grantnumber
- UWTSD
- OAI identifier oai:identifier
- oai:repository.uwtsd.ac.uk:4289