Malicious program detection using distinct textural features and fine-tuned InceptionV3 model

Sanjeev Kumar, Yudhishthira Sapru, Navdeep Singh Chahal · 2024

Various prevalent malware detection methods employ static signature-based detection, dynamic analysis, and other techniques to identify malware. However, these traditional malware detection techniques have become less effective due to sophisticated evasion techniques employed by malware authors. In addition, malware analysis is a highly compute-intensive process. This research introduces a new malware detection architecture that deploys different textural features and transfer learning. In this approach, the entire binary executable program is first converted into a grayscale image before extracting the deep textural features by taking the whole image as input to the convolution neural network (CNN) model. Subsequently, a pre-trained InceptionV3 model is used to extract the textural characteristics of the visualized image. The dimension of feature maps is reduced by customizing the InceptionV3 model and adding fully connected (FC) dense layers. This study performs the feature correlation analysis to select only highly distinct textural features. Finally, the selected feature map trains a softmax classifier to predict unknown malware families. This study conducts the experiments using two well-known public benchmarked datasets-MalImg and Microsoft BIG. The proposed model reported a classification accuracy of $98.57 \%$ using the MalIng data set and an accuracy of $97.78 \%$ for the Microsoft data set. The proposed model is superior to similar approaches in the literature. The minimal computation cost of feature extraction makes it well-suited for malware threat detection in industrial environments. Index Terms-Cybersecurity, Deep learning, Image visualization, Malware detection, Transfer learning

Read the paper · More papers on PaperTik