构建首个面向恶意软件检测的多样化内存数据集,支持智能防御系统训练。
MalVol-25: A Diverse, Labelled and Detailed Volatile Memory Dataset for Malware Detection and Response Testing and Validation
- 在受控环境中自动化执行恶意软件并动态采集内存快照。
- 覆盖多类恶意软件与操作系统,含完整标签与行为特征。
- 适合研究自适应防御、数字取证及自动化威胁响应者使用。
本文针对高级分析技术(如机器学习和代理型AI)对高质量恶意软件数据集的迫切需求,提出一种系统化方法:在受控虚拟环境中自动执行恶意软件,并结合动态监控工具生成数据。所构建的数据集包含多个恶意软件家族和操作系统的清洁与感染内存快照,记录了详细的运行时行为与环境特征。设计中强调伦理与法律合规性,通过自动化与人工双重验证确保数据质量,并提供全面文档以保障可复现性与完整性。其独特结构支持系统状态与转换建模,适用于基于强化学习的恶意软件检测与响应策略开发。该资源对提升自适应网络安全防御与数字取证研究具有重要意义,涵盖多种恶意软件场景,具备广泛应用于事件响应与自动化威胁缓解的潜力。
原文摘要 · Abstract (English)
This paper addresses the critical need for high-quality malware datasets that support advanced analysis techniques, particularly machine learning and agentic AI frameworks. Existing datasets often lack diversity, comprehensive labelling, and the complexity necessary for effective machine learning and agent-based AI training. To fill this gap, we developed a systematic approach for generating a dataset that combines automated malware execution in controlled virtual environments with dynamic monitoring tools. The resulting dataset comprises clean and infected memory snapshots across multiple malware families and operating systems, capturing detailed behavioural and environmental features. Key design decisions include applying ethical and legal compliance, thorough validation using both automated and manual methods, and comprehensive documentation to ensure replicability and integrity. The dataset's distinctive features enable modelling system states and transitions, facilitating RL-based malware detection and response strategies. This resource is significant for advancing adaptive cybersecurity defences and digital forensic research. Its scope supports diverse malware scenarios and offers potential for broader applications in incident response and automated threat mitigation.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。