FastText-Based Local Feature Visualization Algorithm for Merged Image-Based Malware Classification Framework for Cyber Security and Cyber Defense

被引:20
|
作者
Jang, Sejun [1 ]
Li, Shuyu [1 ]
Sung, Yunsick [1 ]
机构
[1] Dongguk Univ Seoul, Dept Multimedia Engn, Seoul 04620, South Korea
关键词
cyber security; deep learning; malware classification; malware visualization; GENERATION ALGORITHM;
D O I
10.3390/math8030460
中图分类号
O1 [数学];
学科分类号
0701 ; 070101 ;
摘要
The importance of cybersecurity has recently been increasing. A malware coder writes malware into normal executable files. A computer is more likely to be infected by malware when users have easy access to various executables. Malware is considered as the starting point for cyber-attacks; thus, the timely detection, classification and blocking of malware are important. Malware visualization is a method for detecting or classifying malware. A global image is visualized through binaries extracted from malware. The overall structure and behavior of malware are considered when global images are utilized. However, the visualization of obfuscated malware is tough, owing to the difficulties encountered when extracting local features. This paper proposes a merged image-based malware classification framework that includes local feature visualization, global image-based local feature visualization, and global and local image merging methods. This study introduces a fastText-based local feature visualization method: First, local features such as opcodes and API function names are extracted from the malware; second, important local features in each malware family are selected via the term frequency inverse document frequency algorithm; third, the fastText model embeds the selected local features; finally, the embedded local features are visualized through a normalization process. Malware classification based on the proposed method using the Microsoft Malware Classification Challenge dataset was experimentally verified. The accuracy of the proposed method was approximately 99.65%, which is 2.18% higher than that of another contemporary global image-based approach.
引用
收藏
页数:13
相关论文
共 22 条
  • [21] A lightweight PolSAR image classification algorithm based on multi-scale feature extraction and local spatial information perception
    Shang, Ronghua
    Hu, Mingwei
    Feng, Jie
    Zhang, Weitong
    Xu, Songhua
    APPLIED SOFT COMPUTING, 2025, 170
  • [22] An innovative malware detection methodology employing the amalgamation of stacked BiLSTM and CNN plus LSTM-based classification networks with the assistance of Mayfly metaheuristic optimization algorithm in cyber-attack
    Srinivasan, Sathiyandrakumar
    Deepalakshmi, P.
    CONCURRENCY AND COMPUTATION-PRACTICE & EXPERIENCE, 2023, 35 (10):