Facebook pixel tracking

The Science and Information (SAI) Organization publishes open-access peer-reviewed journals in computer science and artificial intelligence.

Contact Info
Website thesai.org
Follow Us
Contact Info
Follow Us
Research Article | Open Access |

A Malware Analysis Approach for Identifying Threat Actor Correlation Using Similarity Comparison Techniques

Author 1: Ahmad Naim Irfan Author 2: Suriayati Chuprat Author 3: Mohd Naz'ri Mahrin Author 4: Aswami Ariffin
International Journal of Advanced Computer Science and Applications (IJACSA) · Vol. 15, No. 12 · Published 2024

DOI: https://doi.org/10.14569/IJACSA.2024.0151258

Abstract

Cybersecurity is essential for organisations to protect critical assets from cyber threats in the increasingly digital and interconnected world. However, cybersecurity incidents are rising each year, leading to increased workloads. Current malware analysis approaches are often case-by-case, based on specific scenarios, and are typically limited to identifying malware. When cybersecurity incidents are not handled effectively due to these analytical limitations, operations are disrupted, and an organisation’s brand and client trust are negatively impacted, often resulting in financial loss. The aim of this research is to enhance the analysis of Advanced Persistent Threat (APT) malware by correlating malware with its associated threat actors, such as APT groups, who are the perpetrators or authors of the malware. APT malware represents a highly dangerous threat, and gaining insight into the adversaries behind such attacks is crucial for preventing cyber incidents. This research proposes an advanced malware analysis approach that correlates APT malware with threat actors using a similarity comparison technique. By extracting features from APT malware and analysing the correlation with the threat actor, cybersecurity professionals can implement effective countermeasures to ensure that organisations are better prepared against these sophisticated cyber threats. The solution aims to assist cybersecurity practitioners and researchers in making informed decisions by providing actionable insights and a broader perspective on cyber-attacks, based on detailed information about malware tied to specific threat actors.

Keywords

How to Cite this Article

Irfan, A. N., Chuprat, S., Mahrin, M. N., & Ariffin, A. (2024). A Malware Analysis Approach for Identifying Threat Actor Correlation Using Similarity Comparison Techniques. International Journal of Advanced Computer Science and Applications, 15(12). https://doi.org/10.14569/IJACSA.2024.0151258

Irfan, Ahmad Naim, et al.. "A Malware Analysis Approach for Identifying Threat Actor Correlation Using Similarity Comparison Techniques." International Journal of Advanced Computer Science and Applications, vol. 15, no. 12, 2024, https://doi.org/10.14569/IJACSA.2024.0151258.

@article{Irfan2024,
  title     = {A Malware Analysis Approach for Identifying Threat Actor Correlation Using Similarity Comparison Techniques},
  journal   = {International Journal of Advanced Computer Science and Applications},
  volume    = {15},
  number    = {12},
  year      = {2024},
  publisher = {The Science and Information Organization},
  author    = {Ahmad Naim Irfan and Suriayati Chuprat and Mohd Naz'ri Mahrin and Aswami Ariffin},
  doi       = {10.14569/IJACSA.2024.0151258},
  url       = {https://doi.org/10.14569/IJACSA.2024.0151258}
}

Open Access — licensed under a Creative Commons Attribution 4.0 International License. Unrestricted use, distribution, and reproduction in any medium, even commercially, as long as the original work is properly cited.