Massive Malware Variants Detection Based on Bag-of-words Perceptual Hashing

Jian Qiao Yu · Journal of Physics Conference Series · 2020

Abstract Presently, most widely used malware detection methods use signature with reverse engineering to recognize malware variants. Nevertheless, this approach is problematic because the signatures simply modified by using packers on which compress and/or encrypt the executable code to evade detection. In this paper, we present a novel Bag-of-words perceptual hashing to detect variants. The proposed method visualizes malware binary code as grey-scale image, extracts the Grey-level Co-occurrence Matrix features vector and using Bag-of-words model to generate perceptual hashing for malware variants detection. Experimental results show that, the proposed method has a high accuracy and fast detection speed, and has good resilience to popular packers, which is suitable for massive malware variants detection.

Read the paper · More papers on PaperTik