Calculating distances between Windows malware using siamese neural network embeddings
Clicks: 3
ID: 285508
2021
Article Quality & Performance Metrics
Overall Quality
Not rated
Combines reader engagement with the AI quality analysis. This
article has not been analysed, so there is no overall score —
reader engagement is measured and shown alongside.
Reader Engagement
Steady Performance
0.6
/100
3 views
0 readers
AI Quality Assessment
Not analyzed
Readership in this journal
SteadyRanked #2,124 of 3,757 articles by views in Malay Journal
Most read
Least read
Bar heights use a square-root scale. Only the 120 most-read articles are drawn; the journal has 3,757 in total.
Mint this article as an NFT
Not yet mintedCreate a permanent, verifiable on-chain record of this article on the Scimatic Network. The NFT is held in your Journament account, and you can withdraw it to your own wallet at any time.
5
SUSD
one-off · no wallet required
Abstract
In recent years, the rate of growth of unique Windows malware samples has grown significantly. This rapid growth has made manual inspection of every malware sample an impossible task. One way to minimize this problem is through auto clustering of unknown malware samples into clusters of similar files. Auto clustering done in this way would allow malware researchers to identify large clusters, as well as analyzing entire clusters using only a few representatives of each cluster. Much work has been done in machine learning with regards to the problem of clustering malware samples. However, previous work has mostly focused on clustering into known malware families, or require dynamic features which are prohibitively slow to extract given the amount of new malware samples. This paper proposes training a siamese neural network using engineered static features to generate embeddings that can be used to calculate the distances between malware files. The engineered features would be carefully chosen so that the distances calculated from the resulting embeddings would be resistant to a certain degree of malware metamorphism, as well as generalizing well to Windows files as a whole instead of specific malware families. This would also enable a type of one-shot learning detection, where multiple unknown malware samples can be detected using the distance from a known malicious files.
| Reference Key |
persistent_1760655812_68f179c4d05ac
Use this key to autocite in the manuscript while using
SciMatic Manuscript Manager or Thesis Manager
|
|---|---|
| Authors | Sison, Marc Oliver Tan |
| Journal | Malay Journal |
| Year | 2021 |
| DOI |
DOI not found
|
| URL | |
| Keywords | Keywords not found |
Citations
No citations found. To add a citation, contact the admin at info@scimatic.org
Comments
No comments yet. Be the first to comment on this article.