arrow
Return

Unveiling Malware Visual Patterns: A Self-Analysis Perspective

delete2025-01-01
delete0
PRE
AI
F
Fangtian Zhong
Q
Qin Hu
Y
Yili Jiang
J
Jiaqi Huang
成秀珍 (Xiuzhen Cheng)
DOI:10.1109/TIFS.2025.3611649delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
The widespread usage of Microsoft Windows has unfortunately led to a surge in malware, posing a serious threat to the security and privacy of millions of users. In response, the research community has mobilized, with numerous efforts dedicated to strengthening defenses against these threats. The primary goal of these techniques is to detect malicious software early, preventing attacks before any damage occurs. However, many of these methods either claim that packing has minimal impact on malware detection or fail to address the reliability of their approaches when applied to packed samples. Consequently, they are not capable of assisting victims in handling packed programs or recovering from the damages caused by untimely malware detection. To address these challenges, we propose VisUnpac, a static analysis-based data visualization framework for bolstering attack prevention while aiding recovery post-attack by unveiling malware patterns and offering more detailed information including both malware class and family. Our method includes unpacking packed malware programs, calculating local similarity descriptors based on basic blocks, enhancing correlations between descriptors, and refining them by minimizing noises to obtain self-analysis descriptors. Moreover, we employ machine learning to learn the correlations of self-analysis descriptors through architectural learning for final classification. Our comprehensive evaluation of VisUnpac based on a freshly gathered dataset with over 27,106 samples confirms its capability in accurately classifying malware programs with a precision of 99.7%. Additionally, VisUnpac reveals that most antivirus products in VirusTotal can not handle packed samples properly or provide precise malware classification information. We also achieve over 97% space savings compared to existing data visualization based methods.
Keywords:
Malware classification
malware family
variants
self-analysis

Journal

IEEE Transactions on Information Forensics and Security cover
IEEE Transactions on Information Forensics and Security
IF:
8
Papers:
5.2K
Citations:
2.3W

Organization

S
shandong university
Scholars:
9.3W
Papers: 6.4W
Citations: 94
M
montana state university
Scholars:
428
Papers: 217
Citations: 0
G
Georgia State University
Scholars:
5.4K
Papers: 4.4K
Citations: 9.6K
U
University of Central Missouri
Scholars:
16
Papers: 15
Citations: 120
researcher View more organizations