HIT4Mal: Hybrid image transformation for malware classification
Document Type
Article
Publication Date
11-20-2019
Publication Source
Transactions on Emerging Telecommunications Technologies
Abstract
Modern malware evolves various detection avoidance techniques to bypass the state-of-the-art detection methods. An emerging trend to deal with this issue is the combination of image transformation and machine learning models to classify and detect malware. However, existing works in this field only perform simple image transformation methods. These simple transformations have not considered color encoding and pixel rendering techniques on the performance of machine learning classifiers. In this article, we propose a novel approach to encoding and arranging bytes from binary files into images. These developed images contain statistical (eg, entropy) and syntactic artifacts (eg, strings), and their pixels are filled up using space-filling curves. Thanks to these features, our encoding method surpasses existing methods demonstrated by extensive experiments. In particular, our proposed method achieved 93.01% accuracy using the combination of the entropy encoding and character class scheme on the Hilbert curve.
ISBN/ISSN
2161-3915
Publisher
John Wiley & Sons
Volume
31
Issue
11
Sponsoring Agency
The authors wish to thank the anonymous reviewers for their helpful comments. Duc-Ly Vu and Fabio Massacci have partial received funding from the European Union's Horizon 2020 research and innovation program under grant 675320
eCommons Citation
Vu, Duc-Ly; Nguyen, Trong-Kha; Nguyen, Tam V.; Nguyen, Tu N.; Massacci, Fabio; and Phung, Phu H., "HIT4Mal: Hybrid image transformation for malware classification" (2019). Computer Science Faculty Publications. 233.
https://ecommons.udayton.edu/cps_fac_pub/233
COinS
