Malware Classification with GMM-HMM Models

03/03/2021
by   Jing Zhao, et al.
0

Discrete hidden Markov models (HMM) are often applied to malware detection and classification problems. However, the continuous analog of discrete HMMs, that is, Gaussian mixture model-HMMs (GMM-HMM), are rarely considered in the field of cybersecurity. In this paper, we use GMM-HMMs for malware classification and we compare our results to those obtained using discrete HMMs. As features, we consider opcode sequences and entropy-based sequences. For our opcode features, GMM-HMMs produce results that are comparable to those obtained using discrete HMMs, whereas for our entropy-based features, GMM-HMMs generally improve significantly on the classification results that we have achieved with discrete HMMs.

READ FULL TEXT

page 9

page 11

page 14

research
01/06/2019

Malware Detection Using Dynamic Birthmarks

In this paper, we explore the effectiveness of dynamic analysis techniqu...
research
04/17/2023

IMCDCF: An Incremental Malware Detection Approach Using Hidden Markov Models

The popularity of dynamic malware analysis has grown significantly, as i...
research
03/03/2021

Malware Classification with Word Embedding Features

Malware classification is an important and challenging problem in inform...
research
07/17/2023

Hidden Markov Models with Random Restarts vs Boosting for Malware Detection

Effective and efficient malware detection is at the forefront of researc...
research
03/07/2021

A Comparison of Word2Vec, HMM2Vec, and PCA2Vec for Malware Classification

Word embeddings are often used in natural language processing as a means...
research
08/09/2014

Blind Construction of Optimal Nonlinear Recursive Predictors for Discrete Sequences

We present a new method for nonlinear prediction of discrete random sequ...
research
11/23/2022

Lempel-Ziv Networks

Sequence processing has long been a central area of machine learning res...

Please sign up or login with your details

Forgot password? Click here to reset