比较8种恶意软件转图像方法,发现分类效果主要依赖图像分析能力而非转换细节。
A Comparison of Selected Image Transformation Techniques for Malware Classification
- 测试8种恶意软件转图像技术,统一评估其分类表现
- 多种转换方法在不同模型上表现相近,差异不显著
- 适合关注图像化恶意软件分析的从业者参考
近期大量恶意软件研究采用基于图像的机器学习技术,通常取得良好效果。然而,在应用这些技术前,需将恶意软件样本转化为图像,而目前尚无通用的转换方法。现有文献中的转换策略多为临时性设计,未充分考虑可执行文件特性。本文实验了8种不同的恶意软件转图像技术,并对每种方法测试了多种学习模型。结果表明,尽管转换过程差异明显,但若干转换方法在多种模型上表现相似。这说明图像化恶意软件分类的有效性更依赖于图像分析技术的内在优势,而非具体的转换策略细节。
原文摘要 · Abstract (English)
Recently, a considerable amount of malware research has focused on the use of powerful image-based machine learning techniques, which generally yield impressive results. However, before image-based techniques can be applied to malware, the samples must be converted to images, and there is no generally-accepted approach for doing so. The malware-to-image conversion strategies found in the literature often appear to be ad hoc, with little or no effort made to take into account properties of executable files. In this paper, we experiment with eight distinct malware-to-image conversion techniques, and for each, we test a variety of learning models. We find that several of these image conversion techniques perform similarly across a range of learning models, in spite of the image conversion processes being quite different. These results suggest that the effectiveness of image-based malware classification techniques may depend more on the inherent strengths of image analysis techniques, as opposed to the precise details of the image conversion strategy.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。