arrow
返回

DTMIC: Deep transfer learning for malware image classification

delete2022-02-01
delete50
PRE
AI
S
Sanjeev Kumar *
B
B. Janet
DOI:10.1016/j.jisa.2021.103063delete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
In the ever-changing cyber threat landscape, evolving malware threats demand a new technique for their detection. This paper puts forward a strategy for distinguishing malware programs based on transfer learning procedures. The proposed method, known as DTMIC - deep transfer learning for malware image classification, leverages the capabilities of deep Convolutional Neural Network (CNN) architecture previously trained with ImageNet dataset (> 10 million images) for malware classification. Window's portable executable files (PEs) are converted into grayscale images, with the perception that similar malware families fundamentally show the same characteristics when represented as visualized images. Grayscale images serve as input to the customized deep CNN architecture. Features extracted from the convolutional layers of the deep CNN model are flattened and fed into a fully connected dense layer. In addition, to avoid the overfitting problem that many CNN models face, a regularization technique called Early Stopping is employed to monitor the validation loss with configured parameters. The effectiveness and robustness of the model are evaluated on two benchmark datasets - the MalImg dataset (9339 malware samples of 25 families) and the Microsoft BIG dataset (10868 malware samples of 9 families). DTMIC achieved 98.92% test accuracy for MalImg datasets and 93.19% for Microsoft datasets. For comparative analysis, well-established CNN architectures such as VGG16, VGG19, ResNet50, and Google's inceptionV3 are implemented, both as a feature extractor and a classifier. Experimental results reveal that the proposed DTMIC method outperforms the selected baseline models and is resilient to packed and encrypted malware. Moreover, this study validates the model's efficacy on recent and real-world malware samples collected on Honeypots in the wild, with an accuracy of 96.43%.
Keyword:
Information security
Malware classification
Malware visualization
Deep learning
Transfer learning

期刊

Journal of Information Security and Applications 封面图
Journal of Information Security and Applications
IF:
3.7
论文数:
2.0K
被引数:
4.9K

机构

C
centre for development of advanced computing
学者数:
276
论文数: 176
被引数: 0
N
national institute of technology (nit system)
学者数:
4.0W
论文数: 3.7W
被引数: 31
引用论文

引用论文

Image-Based malware classification using ensemble of CNN architectures (IMCEC)
err2020-05-01
err239
PREAI
errVasan, Danish; Alazab, Mamoun; Wassan, Sobia; Safaei, Babak; Zheng, Qin
err分享
err收藏
Static malware detection and attribution in android byte-code through an end-to-end deep system
err2020-01-01
err70
PREAI
errAmin, Muhammad; Tanveer, Tamleek Ali; Tehseen, Mohammad; Khan, Murad; Khan, Fakhri Alam; Anwar, Sajid
err分享
err收藏
Multifrequency EPR Study of Metallofullerenes:  Eu@C82 and Eu@C74
err2004-08-20
err0
PREAI
errHideto Matsuoka; Norio Ozawa; Takeshi Kodama; Hiroyuki Nishikawa; Isao Ikemoto; Koichi Kikuchi; Ko Furukawa; Kazunobu Sato; Daisuke Shiomi; Takeji Takui; Tatsuhisa Kato
err分享
err收藏
Conversion of a Hydrido–Butenylcarbyne Complex to η2-Allene-Coordinated Complexes and Metallabenzenes
err2013-07-03
err0
PREAI
errJinxiang Chen; Chunhong Zhang; Tingwan Xie; Ting Bin Wen; Hong Zhang; Haiping Xia
err分享
err收藏
学者 查看更多内容