Research on a next-generation malware information collection architecture for cybercrime investigation
Architecture design research that applies MALGUARD (a next-generation dynamic malware analysis system) to cyber investigation
This is theoretical architecture research. Building and validating an actual system was proposed as follow-up work.

Written by N@D4, a researcher at ZiPIDA.
This write-up covers architecture design research that applies MALGUARD (a next-generation dynamic malware analysis system) to cyber investigation.
Overview
Cybercrime has recently become more sophisticated through a variety of new techniques, such as virtualization technology and evading tracking of distribution sites, making it increasingly difficult to track and detect.
Companies in Korea and abroad are suffering heavy damage, but existing, traditional analysis methods such as static analysis are limited when it comes to analyzing such malware and tracking its distributors.
Moreover, in the field of cyber investigation, analyzing the malware itself is important, but tracking its distributors is an even more important issue.
This research describes a malware information collection architecture that combines traditional methods, such as static analysis, with the latest information collection methods, such as threat intelligence and OSINT, to track malware distributors efficiently.
Malware analysis method #1
Intelligence
Threat intelligence can be defined as a platform that shares data collected from security incidents and threat information as meaningful information.
Threat intelligence list
OSINT
OSINT can be defined as a platform that collects publicly available data from a variety of information sources.
Its sources include mass media, public data, and professional and academic materials.
OSINT list
Malware analysis method #2
Machine learning
Machine learning is a method that uses algorithms to learn from input data.
Machine learning
Supervised learning
Classification
Regression
Unsupervised learning
Clustering

To analyze malware with machine learning:
- Each
featureof the files to be analyzed must be extracted. - The extracted features are preprocessed, and feature selection is performed to raise the malware detection rate.
- Correlation analysis is then used to select the features that are meaningful for detecting malware.
- Training is performed with machine learning algorithms and the detection rate and accuracy are checked; repeating the steps above can resolve problems that lower accuracy, such as overfitting.
Malware analysis method #3
Dynamic analysis
Dynamic analysis is intended to overcome the limitations of static malware analysis.
In particular, when analyzing malware that uses techniques to evade detection by antivirus software, dynamic analysis can counter the obfuscation techniques that static analysis runs into.
An emulator or a virtual machine (VM) is mainly used to see how malware actually affects the system when it runs.
Application
For cyber investigation, it is not enough simply to analyze malware as discussed above: it must be possible to identify distributors through link analysis of the malware’s features and the characteristics of its malicious behavior.
The table below shows the stage-by-stage malware analysis architecture based on cyber investigation:
- Stage 1: Malware analysis information is collected through the analysis engine.
- Stage 2: Smart filtering keeps only the information needed for cyber investigation, and the characteristics of the analyzed malware are extracted and normalized.
- Stage 3: Information linked to open-source intelligence and to big data is collected through OSINT and threat intelligence. The earlier analysis results for the malware itself are then combined with the OSINT and threat intelligence information through link analysis, so that the essential feature information needed for cyber investigation is collected and derived.
- Stage 4: Link analysis of the information from stages 1–3 extracts meaning relevant to cyber investigation, giving cyber investigators a basis for using information about the malware itself to track its distributors.
| Stage 1 analysis engine | Stage 2 smart filtering | Stage 3 OSINT and Intelligence | Stage 4 link analysis | |
|---|---|---|---|---|
| Concept |
|
|
|
|
| Details |
|
|
| Analysis results
|
| Software and algorithms |
Tools
| Filter
| OSINT
Intelligence
|
Conclusion
Most cybercrime today is carried out with malware, but existing methods are limited in their ability to rapidly analyze increasingly sophisticated malware and track its distributors.
We therefore researched a next-generation analysis platform architecture capable of linked analysis through threat intelligence and OSINT, in order to track the distributors of sophisticated malware.
However, because the scope of the research and analysis was vast and experiments through implementation were limited, we limited the work to a theoretical study.
In the future, we plan to address the shortcomings by building an actual system and to validate its value as a next-generation cyber investigation platform.