Date of Award
2026
Document Type
Thesis
Degree Name
Master of Science (MS)
Department
Computer Science
Committee Chair
Bramwell Brizendine
Committee Member
Letha Etzkorn
Committee Member
Tathagata Mukherjee
Research Advisor
Bramwell Brizendine
Subject(s)
Malware (Computer software), Data encryption (Computer science), Computers--Access control, Computer security
Abstract
Modern malware campaigns operate in stages across diverse formats, including PE, ELF, shellcode, and malicious documents, some leveraging steganography to deliver payloads such as Quasar RAT and Lokibot. Because analysis tooling remains siloed by artifact type, analysts struggle to identify shared code reuse, behavioral overlap, and campaign relationships when adversaries avoid traditional indicators. This thesis presents INFLEX, a framework that normalizes diverse artifacts through a unified pipeline combining static analysis, emulated behavioral extraction, sandbox execution, and threat intelligence enrichment. Its correlation layer introduces Variant Resilient Function Hashing (VRFH), validated against fuzzy hashing baselines on targeted samples, and Weighted Artifact Fusion for Triage (WAFT), which clusters unassociated samples into coherent groups potentially revealing campaign connections. Evaluated on 370 samples across twelve malware families, INFLEX reached 60\% family agreement with community references and recovered steganographic payloads hidden across staged delivery mechanisms, while ELF verdict scoring remained constrained by limited rule coverage.
Recommended Citation
Bower, Luke, "INFLEX : A scalable framework for malware analysis, correlation, and steganography detection" (2026). Theses. 858.
https://louis.uah.edu/uah-theses/858