loading
Papers Papers/2022 Papers Papers/2022

Research.Publish.Connect.

Paper

Paper Unlock

Authors: Martin Jureček ; Olha Jurečková and Róbert Lórencz

Affiliation: Faculty of Information Technology, Czech Technical University in Prague, Czech Republic

Keyword(s): Malware Family, PE File Format, Distance Metric Learning, Machine Learning.

Abstract: The objective of malware family classification is to assign a tested sample to the correct malware family. This paper concerns the application of selected state-of-the-art distance metric learning techniques to malware families classification. The goal of distance metric learning algorithms is to find the most appropriate distance metric parameters concerning some optimization criteria. The distance metric learning algorithms considered in our research learn from metadata, mostly contained in the headers of executable files in the PE file format. Several experiments have been conducted on the dataset with 14,000 samples consisting of six prevalent malware families and benign files. The experimental results showed that the average precision and recall of the k -Nearest Neighbors algorithm using the distance learned on training data were improved significantly comparing when the non-learned distance was used. The k -Nearest Neighbors classifier using the Mahalanobis distance metric lea rned by the Metric Learning for Kernel Regression method achieved average precision and recall, both of 97.04% compared to Random Forest with a 96.44% of average precision and 96.41% of average recall, which achieved the best classification results among the state-of-the-art ML algorithms considered in our experiments. (More)

CC BY-NC-ND 4.0

Sign In Guest: Register as new SciTePress user now for free.

Sign In SciTePress user: please login.

PDF ImageMy Papers

You are not signed in, therefore limits apply to your IP address 3.140.184.203

In the current month:
Recent papers: 100 available of 100 total
2+ years older papers: 200 available of 200 total

Paper citation in several formats:
Jureček, M., Jurečková, O. and Lórencz, R. (2021). Improving Classification of Malware Families using Learning a Distance Metric. In Proceedings of the 7th International Conference on Information Systems Security and Privacy - ICISSP; ISBN 978-989-758-491-6; ISSN 2184-4356, SciTePress, pages 643-652. DOI: 10.5220/0010326306430652

@conference{icissp21,
author={Martin Jureček and Olha Jurečková and Róbert Lórencz},
title={Improving Classification of Malware Families using Learning a Distance Metric},
booktitle={Proceedings of the 7th International Conference on Information Systems Security and Privacy - ICISSP},
year={2021},
pages={643-652},
publisher={SciTePress},
organization={INSTICC},
doi={10.5220/0010326306430652},
isbn={978-989-758-491-6},
issn={2184-4356},
}

TY - CONF

JO - Proceedings of the 7th International Conference on Information Systems Security and Privacy - ICISSP
TI - Improving Classification of Malware Families using Learning a Distance Metric
SN - 978-989-758-491-6
IS - 2184-4356
AU - Jureček, M.
AU - Jurečková, O.
AU - Lórencz, R.
PY - 2021
SP - 643
EP - 652
DO - 10.5220/0010326306430652
PB - SciTePress