EconPapers    
Economics at your fingertips  
 

Fine-Grained Behavioral Analysis for Malware Detection in Containerized Environments

Khaja Kamaluddin ()

American Journal of Computing and Engineering, 2021, vol. 4, issue 4, 1-20

Abstract: Purpose: Containerized environments have become foundational to modern software development due to their portability, scalability, and efficient resource utilization. However, their shared-kernel architecture introduces distinct security challenges, particularly in malware detection. This study presents a historical analysis of fine-grained, behavior-based malware detection techniques within containerized systems. Materials and Methods: We examine early machine learning approaches, including Decision Trees, Hidden Markov Models, and LSTM networks trained with limited datasets alongside system call tracing and process behavior profiling. Findings: While these techniques are now outdated, they marked critical early steps beyond static and signature-based detection in dynamic, containerized infrastructures. We analyse behavioural features such as syscall sequences, memory anomalies, and DNS irregularities, assessing their detection performance and limitations in orchestrated environments. The paper further contextualizes these legacy methods in light of modern advancements, including eBPF-based monitoring and context-aware deep learning models. Unique Contribution to Theory, Practice and Policy: Key recommendations include leveraging eBPF for efficient runtime monitoring, incorporating orchestration metadata for context-aware detection, and enabling cross-container correlation for identifying lateral movement. This retrospective establishes a comparative framework that informs the development of adaptive, real-time security solutions, such as graph neural networks and behavioural baselining, thereby guiding future research in runtime container security.

Date: 2021
References: Add references at CitEc
Citations:

Downloads: (external link)
https://ajpojournals.org/journals/index.php/AJCE/article/view/2725 (application/pdf)

Related works:
This item may be available elsewhere in EconPapers: Search for items with the same title.

Export reference: BibTeX RIS (EndNote, ProCite, RefMan) HTML/Text

Persistent link: https://EconPapers.repec.org/RePEc:bfy:ojajce:v:4:y:2021:i:4:p:1-20:id:2725

Access Statistics for this article

More articles in American Journal of Computing and Engineering from AJPO Journals Limited
Bibliographic data for series maintained by Chief Editor ().

 
Page updated 2025-06-28
Handle: RePEc:bfy:ojajce:v:4:y:2021:i:4:p:1-20:id:2725