{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,18]],"date-time":"2026-07-18T19:50:35Z","timestamp":1784404235414,"version":"3.55.0"},"reference-count":21,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2026,1,4]],"date-time":"2026-01-04T00:00:00Z","timestamp":1767484800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2026,1,4]],"date-time":"2026-01-04T00:00:00Z","timestamp":1767484800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["60903220"],"award-info":[{"award-number":["60903220"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Cybersecurity"],"abstract":"<jats:title>Abstract<\/jats:title>\n                  <jats:p>To overcome the significant challenges posed by new variants of malware to conventional detection techniques, such as low automation, reliance on expert knowledge, and inadequate capability to detect unknown threats in existing memory analysis methods, this paper designs an intelligent detection algorithm for malicious memory segments based on a one-dimensional convolutional network. This algorithm takes raw memory byte sequences as input, referred to as memory segments, and employs a one-dimensional convolutional neural network to automatically learn their deep features and inherent relationships. This approach facilitates an end-to-end automated analysis from data to detection, thereby eliminating the need for complex manual feature engineering. Experimental results show that the designed algorithm achieves a maximum accuracy of 98.28%, precision of 98.94%, recall of 97.6%, F1-score of 0.9826, and AUC value of 0.9972 on the test set, showcasing outstanding detection performance and generalization capability for malicious memory segments. This research offers a novel and effective method for efficient and accurate memory-based malware detection, which can significantly enhance proactive security defense capabilities.<\/jats:p>","DOI":"10.1186\/s42400-025-00537-4","type":"journal-article","created":{"date-parts":[[2026,1,4]],"date-time":"2026-01-04T09:24:56Z","timestamp":1767518696000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":2,"title":["Intelligent malware detection method based on memory segments"],"prefix":"10.1186","volume":"9","author":[{"given":"Shilong","family":"Yu","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Binglong","family":"Li","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yong","family":"Zhao","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yanru","family":"Chen","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yifeng","family":"Sun","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Heyu","family":"Chang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2026,1,4]]},"reference":[{"key":"537_CR1","unstructured":"Binglong L, Jinlong T, Yu Z, Yifeng S, Qingxian W, Chaowen C (2021) Auto forensic detecting algorithms of malicious code fragment based on tensorflow. Chinese Journal of Network & Information Security 7(4)"},{"issue":"3","key":"537_CR2","doi-asserted-by":"publisher","first-page":"758","DOI":"10.3390\/sym15030758","volume":"15","author":"S Zhang","year":"2023","unstructured":"Zhang S, Hu C, Wang L, Mihaljevic MJ, Xu S, Lan T (2023) A malware detection approach based on deep learning and memory forensics. Symmetry 15(3):758","journal-title":"Symmetry"},{"key":"537_CR3","doi-asserted-by":"crossref","unstructured":"Khalid Z, Iqbal F, Al-Hussaeni K, Macdermott A, Hussain M (2022) Forensic analysis of microsoft teams: Investigating memory, disk and network. Lecture Notes of the Institute for Computer Sciences, Social Informatics and Telecommunications Engineering, 583\u2013601","DOI":"10.1007\/978-3-031-06371-8_37"},{"key":"537_CR4","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2020.102166","volume":"103","author":"AS Bozkir","year":"2021","unstructured":"Bozkir AS, Tahillioglu E, Aydos M, Kara I (2021) Catch them alive: a malware detection approach through memory forensics, manifold learning and computer vision. Comput Secur 103:102166","journal-title":"Comput Secur"},{"issue":"5","key":"537_CR5","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3329786","volume":"52","author":"O Or-Meir","year":"2019","unstructured":"Or-Meir O, Nissim N, Elovici Y, Rokach L (2019) Dynamic malware analysis in the modern era a state of the art survey. ACM Comput Surv (CSUR) 52(5):1\u201348","journal-title":"ACM Comput Surv (CSUR)"},{"key":"537_CR6","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2019.101590","volume":"87","author":"N Nissim","year":"2019","unstructured":"Nissim N, Lahav O, Cohen A, Elovici Y, Rokach L (2019) Volatile memory analysis using the minhash method for efficient and secured detection of malware in private cloud. Comput Secur 87:101590","journal-title":"Comput Secur"},{"key":"537_CR7","doi-asserted-by":"publisher","first-page":"112588","DOI":"10.1109\/ACCESS.2019.2934012","volume":"7","author":"Y Dai","year":"2019","unstructured":"Dai Y, Li H, Qian Y, Yang R, Zheng M (2019) Smash: a malware detection method based on multi-feature ensemble learning. IEEE Access 7:112588\u2013112597","journal-title":"IEEE Access"},{"key":"537_CR8","doi-asserted-by":"publisher","first-page":"23","DOI":"10.1016\/j.ins.2016.07.019","volume":"379","author":"Y Cheng","year":"2017","unstructured":"Cheng Y, Fu X, Du X, Luo B, Guizani M (2017) A lightweight live memory forensic approach based on hardware virtualization. Inf Sci 379:23\u201341","journal-title":"Inf Sci"},{"key":"537_CR9","doi-asserted-by":"crossref","unstructured":"Kirkland J, Stoddard R, Antonov B, Dragomirov N, Belmonte A (2024) Automated detection of crypto ransomware using machine learning and file entropy analysis. Authorea Preprints","DOI":"10.36227\/techrxiv.172833027.76280291\/v1"},{"key":"537_CR10","doi-asserted-by":"crossref","unstructured":"Lerivi V, Vasquez E, Hoffmann L, Caruso A (2024) Implementing a pass-through mechanism to mitigate ransomware-induced encryption on ntfs","DOI":"10.21203\/rs.3.rs-5109992\/v1"},{"key":"537_CR11","doi-asserted-by":"crossref","unstructured":"Skalski K, Dombrokova K, Szczawinski W (2024) Situational aware access control to prevent android malware","DOI":"10.31219\/osf.io\/e2txw"},{"issue":"2","key":"537_CR12","first-page":"46","volume":"5","author":"HJ Jin","year":"2023","unstructured":"Jin HJ, Hibbins C (2023) Effective ransomware attacks detection using cnn algorithm. Int J Inform Comput 5(2):46\u201350","journal-title":"Int J Inform Comput"},{"issue":"1","key":"537_CR13","doi-asserted-by":"publisher","first-page":"53","DOI":"10.1186\/s40537-021-00444-8","volume":"8","author":"L Alzubaidi","year":"2021","unstructured":"Alzubaidi L, Zhang J, Humaidi AJ, Al-Dujaili A, Duan Y, Al-Shamma O, Santamar\u00eda J, Fadhel MA, Al-Amidie M, Farhan L (2021) Review of deep learning: concepts, cnn architectures, challenges, applications, future directions. J Big Data 8(1):53","journal-title":"J Big Data"},{"key":"537_CR14","volume":"33","author":"R Palutke","year":"2020","unstructured":"Palutke R, Block F, Reichenberger P, Stripeika D (2020) Hiding process memory via anti-forensic techniques. Forensic Sci Int Digit Investig 33:301012","journal-title":"Forensic Sci Int Digit Investig"},{"key":"537_CR15","doi-asserted-by":"publisher","DOI":"10.1016\/j.eswa.2022.119133","volume":"214","author":"I Kara","year":"2023","unstructured":"Kara I (2023) Fileless malware threats: recent advances, analysis approach through memory forensics and research challenges. Expert Syst Appl 214:119133","journal-title":"Expert Syst Appl"},{"key":"537_CR16","volume":"32","author":"D Uroz","year":"2020","unstructured":"Uroz D, Rodr\u00edguez RJ (2020) On challenges in verifying trusted executable files in memory forensics. Forensic Sci Int Digit Investig 32:300917","journal-title":"Forensic Sci Int Digit Investig"},{"key":"537_CR17","doi-asserted-by":"publisher","DOI":"10.22541\/au.172901014.44599790\/v1","volume-title":"Ransomware detection in network traffic using a hybrid cnn and isolation forest approach","author":"A Lumazine","year":"2024","unstructured":"Lumazine A, Drakos G, Salvatore M, Armand V, Andros B, Castiglione R, Grigorescu E (2024) Ransomware detection in network traffic using a hybrid cnn and isolation forest approach. Sage Publishing, Thousand Oaks, CA, USA"},{"key":"537_CR18","doi-asserted-by":"crossref","unstructured":"Odeh A, Taleb AA, Alhajahjeh T, Navarro F (2025) Advanced memory forensics for malware classification with deep learning algorithms. Cluster Computing","DOI":"10.1007\/s10586-025-05104-7"},{"key":"537_CR19","doi-asserted-by":"publisher","first-page":"104177","DOI":"10.1016\/j.cose.2024.104177","volume":"148","author":"P Wu","year":"2025","unstructured":"Wu P, Gao M, Sun F, Wang X, Pan L (2025) Multi-perspective api call sequence behavior analysis and fusion for malware classification. Comput Secur 148:104177","journal-title":"Comput Secur"},{"issue":"1","key":"537_CR20","doi-asserted-by":"publisher","first-page":"167","DOI":"10.3390\/electronics14010167","volume":"14","author":"S Zhang","year":"2025","unstructured":"Zhang S, Gao M, Wang L, Xu S, Shao W, Kuang R (2025) A malware-detection method using deep learning to fully extract api sequence features. Electronics 14(1):167","journal-title":"Electronics"},{"key":"537_CR21","doi-asserted-by":"crossref","unstructured":"Yang L, Ciptadi A, Laziuk I, Ahmadzadeh A, Wang G (2021) Bodmas: an open dataset for learning based temporal analysis of pe malware. In: 2021 IEEE Security and Privacy Workshops (SPW), IEEE, pp 78\u201384","DOI":"10.1109\/SPW53761.2021.00020"}],"container-title":["Cybersecurity"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s42400-025-00537-4.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1186\/s42400-025-00537-4","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s42400-025-00537-4.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,1,4]],"date-time":"2026-01-04T09:24:58Z","timestamp":1767518698000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1186\/s42400-025-00537-4"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,1,4]]},"references-count":21,"journal-issue":{"issue":"1","published-online":{"date-parts":[[2026,12]]}},"alternative-id":["537"],"URL":"https:\/\/doi.org\/10.1186\/s42400-025-00537-4","relation":{},"ISSN":["2523-3246"],"issn-type":[{"value":"2523-3246","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,1,4]]},"assertion":[{"value":"30 October 2025","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"11 December 2025","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"4 January 2026","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declaration"}},{"value":"Not applicable.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Ethics approval and consent to participate"}},{"value":"Not applicable.","order":3,"name":"Ethics","group":{"name":"EthicsHeading","label":"Consent for publication"}},{"value":"The authors declare no conflict of interest.","order":4,"name":"Ethics","group":{"name":"EthicsHeading","label":"Competing interests"}}],"article-number":"5"}}